New DOUBLECUP ClickFix service hides malware in browser cache images

Summary

A new Russian loader-as-a-service called DOUBLECUP is employing ClickFix attacks to conceal malware within browser cache images. This tactic ultimately leads to the deployment of CountLoader on Windows and macOS, and a new remote access trojan known as DeviceManager specifically on Windows systems.

IFF Assessment

FOE

This article details a new malware delivery technique that compromises user systems, posing a direct threat to defenders.

Defender Context

Defenders should be aware of new obfuscation techniques like hiding malware in browser cache images. This method bypasses traditional file-based detection and requires monitoring for unusual network traffic patterns or unexpected browser behavior that could indicate compromise.

Read Full Story →