Executive Summary
In August 2026, a Russian Loader-as-a-Service (LaaS) named DOUBLECUP was identified utilizing ClickFix lures to embed steganographic PNG images into victims' browser caches. This method facilitated the delivery of CountLoader and a new remote access trojan, DeviceManager. The attack sequence involved dropping a PNG image into the browser cache, extracting hidden content, and executing a second-stage payload that decrypted the final malware using the victim's public IP address as a cryptographic key. DeviceManager employed EtherHiding to resolve its command-and-control infrastructure, communicating over HTTP or DNS tunneling. The DOUBLECUP service, active since June 2026, provided operators with licenses and client agents to create campaigns by embedding code into ClickFix landing pages. Each license included metadata such as the client's IP address, active days, label, and version, allowing multiple campaigns per license. The service also featured a Windows GUI client for configuration updates and command issuance. Campaigns leveraging DOUBLECUP impersonated CRM login pages, including NetSuite, Odoo, HubSpot, and Salesforce, to deliver the loader via embedded iframe elements. This approach led to the execution of ClickFix commands that searched the browser cache for the PNG image, extracted malicious scripts, and launched subsequent payloads. The attack chain concluded with the stager reconstructing and executing the final payload, establishing persistence, and exfiltrating system metadata. The emergence of DOUBLECUP underscores the evolving sophistication of cyber threats, particularly the use of steganography and environmental keying to evade detection. The integration of ClickFix lures with advanced payload delivery mechanisms highlights the need for enhanced security measures and user awareness to mitigate such threats.
Why This Matters Now
The emergence of DOUBLECUP underscores the evolving sophistication of cyber threats, particularly the use of steganography and environmental keying to evade detection. The integration of ClickFix lures with advanced payload delivery mechanisms highlights the need for enhanced security measures and user awareness to mitigate such threats.
Attack Path Analysis
The DOUBLECUP attack begins with users visiting malicious ClickFix sites that drop steganographic PNG images into their browser cache, leading to the execution of hidden scripts. These scripts decrypt and execute payloads like CountLoader and DeviceManager RAT, establishing persistence and enabling further malicious activities. The malware utilizes techniques such as EtherHiding to resolve command-and-control infrastructure and communicate covertly over HTTP or DNS tunneling. The attack culminates in the exfiltration of sensitive data and potential system compromise.
Kill Chain Progression
Initial Compromise
Description
Users visit malicious ClickFix sites that drop steganographic PNG images into their browser cache, leading to the execution of hidden scripts.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Data Obfuscation: Steganography
Execution Guardrails: Environmental Keying
Application Layer Protocol: Web Protocols
User Execution: Malicious Link
Ingress Tool Transfer
Command and Scripting Interpreter: PowerShell
Encrypted Channel: Symmetric Cryptography
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data Protection
Control ID: Pillar 3: Data
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
CRM impersonation attacks targeting NetSuite and Salesforce create high risk for financial institutions using these platforms for customer data management.
Computer Software/Engineering
DOUBLECUP's VS Code extension and steganographic techniques directly threaten software development environments with loader-as-a-service malware delivery mechanisms.
Computer/Network Security
Advanced evasion techniques including environmental keying and EtherHiding challenge traditional security controls, requiring enhanced egress filtering and anomaly detection capabilities.
Marketing/Advertising/Sales
ClickFix campaigns impersonating CRM platforms like HubSpot and Salesforce directly target marketing operations through social engineering and browser-based payload delivery.
Sources
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAThttps://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.htmlVerified
- Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATshttps://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/Verified
- Trojan.CountLoaderhttps://www.malwarebytes.com/blog/detections/trojan-countloaderVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the DOUBLECUP attack as it can limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise may be constrained by limiting the execution of unauthorized scripts and restricting access to malicious sites.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts could be limited by enforcing strict segmentation policies that restrict unauthorized access to sensitive resources.
Control: East-West Traffic Security
Mitigation: Lateral movement within the network could be constrained by monitoring and controlling east-west traffic, reducing the attacker's ability to compromise additional systems.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications may be limited by providing visibility and control over network traffic, detecting and blocking covert channels.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts could be constrained by enforcing egress policies that monitor and control outbound traffic, reducing the risk of data loss.
The overall impact of the attack may be reduced by limiting the attacker's ability to move laterally and exfiltrate data, thereby reducing the potential for system compromise and data loss.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management (CRM)
- Sales Operations
- Marketing Campaigns
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of customer data, including contact information and sales records.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline intrusion prevention systems (IPS) to detect and block known exploit patterns and malicious payloads.
- • Enforce zero trust segmentation to limit lateral movement within the network.
- • Utilize egress security and policy enforcement to control outbound traffic and prevent unauthorized data exfiltration.
- • Deploy multicloud visibility and control solutions to monitor and manage traffic across cloud environments.
- • Establish threat detection and anomaly response mechanisms to identify and respond to suspicious activities promptly.



