Executive Summary
In August 2026, a Russian loader-as-a-service named DOUBLECUP was identified leveraging ClickFix attacks to embed malicious code within PNG images cached by victims' browsers. This method facilitated the delivery of CountLoader to both Windows and macOS devices, and a new remote access trojan named DeviceManager to Windows systems. The DOUBLECUP service provided clients with tools to create malicious campaigns, handling infrastructure aspects such as hosting steganographic images and managing encryption keys. Attackers used fake CAPTCHA prompts on impersonated login pages to trick users into executing commands that extracted and ran the hidden payloads from the browser cache.
This incident underscores the evolving sophistication of malware delivery mechanisms, particularly the use of steganography and social engineering to bypass traditional security measures. The rise of loader-as-a-service platforms like DOUBLECUP highlights the increasing accessibility of advanced attack tools to a broader range of threat actors, necessitating enhanced vigilance and adaptive defense strategies.
Why This Matters Now
The emergence of services like DOUBLECUP signifies a shift towards more accessible and sophisticated malware deployment methods, enabling a wider array of threat actors to execute complex attacks. This trend demands immediate attention to bolster defenses against such advanced techniques.
Attack Path Analysis
The DOUBLECUP ClickFix attack begins with users visiting compromised websites that display fake CAPTCHA prompts, leading to the download of malicious PNG images into the browser cache. Users are then tricked into executing commands that extract and run hidden malware from these images, resulting in the installation of CountLoader and DeviceManager RAT, which establish persistence and enable remote control. The malware communicates with command and control servers using techniques like EtherHiding to evade detection. Sensitive data is exfiltrated through encrypted channels, and the attackers maintain control over the compromised systems, potentially leading to further exploitation.
Kill Chain Progression
Initial Compromise
Description
Users visit compromised websites displaying fake CAPTCHA prompts, leading to the download of malicious PNG images into the browser cache.
MITRE ATT&CK® Techniques
Obfuscated Files or Information: Steganography
Hide Artifacts
Masquerading
User Execution: Malicious Link
Command and Scripting Interpreter
Ingress Tool Transfer
Application Layer Protocol: Web Protocols
Encrypted Channel: Symmetric Cryptography
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data Protection
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
DOUBLECUP loader-as-a-service targeting browser cache with steganographic PNG images threatens software development environments through ClickFix social engineering attacks delivering CountLoader and DeviceManager RAT payloads.
Financial Services
Fake CAPTCHA prompts impersonating platforms like NetSuite and Salesforce specifically target financial service login pages, enabling credential theft and system compromise through browser-cached malware delivery mechanisms.
Information Technology/IT
Cross-platform CountLoader targeting Windows and macOS systems poses significant risk to IT infrastructure through fileless execution, persistence mechanisms, and cryptocurrency wallet harvesting capabilities across enterprise environments.
Marketing/Advertising/Sales
HubSpot and Salesforce impersonation attacks directly threaten marketing platforms while DeviceManager RAT's blockchain-based C2 infrastructure enables persistent compromise of sales and customer relationship management systems.
Sources
- New DOUBLECUP ClickFix service hides malware in browser cache imageshttps://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/Verified
- Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATshttps://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/Verified
- ClickFix is changing the economics of social engineeringhttps://www.helpnetsecurity.com/2026/07/15/clickfix-social-engineering-attacks-report/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the DOUBLECUP ClickFix attack as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the reach of malicious downloads by enforcing strict segmentation, reducing the potential for malware to spread beyond the initial compromised workload.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the malware's ability to escalate privileges by enforcing strict identity-based access controls, reducing unauthorized access.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit lateral movement by enforcing strict segmentation, reducing the malware's ability to communicate with other workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit unauthorized outbound communications by enforcing strict egress policies, reducing the malware's ability to establish command and control channels.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit data exfiltration by enforcing strict outbound traffic policies, reducing unauthorized data transfers.
The CNSF would likely limit the attacker's control by enforcing strict segmentation and access controls, reducing the scope of potential exploitation.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management (CRM)
- Enterprise Resource Planning (ERP)
- Sales and Marketing Platforms
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive customer and corporate data, including PII and financial records.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities.
- • Enforce East-West Traffic Security to prevent unauthorized internal communications.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.



