DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
Summary
A new Russian loader-as-a-service named DOUBLECUP is employing a novel technique to deliver malware. It uses "ClickFix" lures to stage malicious PNG images within a victim's browser cache, from which it then extracts and executes further payloads, including CountLoader and a new remote access trojan called DeviceManager.
IFF Assessment
The discovery of a new loader-as-a-service utilizing sophisticated evasion techniques to deliver malware poses a direct threat to defenders.
Defender Context
Defenders should be aware of this new DOUBLECUP loader and its use of steganography within PNG files and browser cache manipulation. This technique can bypass traditional signature-based detection methods for initial stages of infection, requiring vigilance in analyzing network traffic and endpoint behavior for unusual file handling and process execution.