Validated Containment Architectures are here. →Explore

Executive Summary

In August 2026, a Russian Loader-as-a-Service (LaaS) named DOUBLECUP was identified utilizing ClickFix lures to embed steganographic PNG images into victims' browser caches. This method facilitated the delivery of CountLoader and a new remote access trojan, DeviceManager. The attack sequence involved dropping a PNG image into the browser cache, extracting hidden content, and executing a second-stage payload that decrypted the final malware using the victim's public IP address as a cryptographic key. DeviceManager employed EtherHiding to resolve its command-and-control infrastructure, communicating over HTTP or DNS tunneling. The DOUBLECUP service, active since June 2026, provided operators with licenses and client agents to create campaigns by embedding code into ClickFix landing pages. Each license included metadata such as the client's IP address, active days, label, and version, allowing multiple campaigns per license. The service also featured a Windows GUI client for configuration updates and command issuance. Campaigns leveraging DOUBLECUP impersonated CRM login pages, including NetSuite, Odoo, HubSpot, and Salesforce, to deliver the loader via embedded iframe elements. This approach led to the execution of ClickFix commands that searched the browser cache for the PNG image, extracted malicious scripts, and launched subsequent payloads. The attack chain concluded with the stager reconstructing and executing the final payload, establishing persistence, and exfiltrating system metadata. The emergence of DOUBLECUP underscores the evolving sophistication of cyber threats, particularly the use of steganography and environmental keying to evade detection. The integration of ClickFix lures with advanced payload delivery mechanisms highlights the need for enhanced security measures and user awareness to mitigate such threats.

Why This Matters Now

The emergence of DOUBLECUP underscores the evolving sophistication of cyber threats, particularly the use of steganography and environmental keying to evade detection. The integration of ClickFix lures with advanced payload delivery mechanisms highlights the need for enhanced security measures and user awareness to mitigate such threats.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

DOUBLECUP is a Russian Loader-as-a-Service (LaaS) identified in August 2026, utilizing ClickFix lures and steganographic techniques to deliver malware such as CountLoader and DeviceManager RAT.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to the DOUBLECUP attack as it can limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The initial compromise may be constrained by limiting the execution of unauthorized scripts and restricting access to malicious sites.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Privilege escalation attempts could be limited by enforcing strict segmentation policies that restrict unauthorized access to sensitive resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement within the network could be constrained by monitoring and controlling east-west traffic, reducing the attacker's ability to compromise additional systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control communications may be limited by providing visibility and control over network traffic, detecting and blocking covert channels.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts could be constrained by enforcing egress policies that monitor and control outbound traffic, reducing the risk of data loss.

Impact (Mitigations)

The overall impact of the attack may be reduced by limiting the attacker's ability to move laterally and exfiltrate data, thereby reducing the potential for system compromise and data loss.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management (CRM)
  • Sales Operations
  • Marketing Campaigns
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of customer data, including contact information and sales records.

Recommended Actions

  • Implement inline intrusion prevention systems (IPS) to detect and block known exploit patterns and malicious payloads.
  • Enforce zero trust segmentation to limit lateral movement within the network.
  • Utilize egress security and policy enforcement to control outbound traffic and prevent unauthorized data exfiltration.
  • Deploy multicloud visibility and control solutions to monitor and manage traffic across cloud environments.
  • Establish threat detection and anomaly response mechanisms to identify and respond to suspicious activities promptly.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image