Threat reportMalwareTL-2026-1847
DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganography
DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in (TL-2026-1847) is a high-severity malware campaign, first published 2026-08-03. It is attributed to DOUBLECUP Operation (Russia) with medium confidence, affects Microsoft Windows (10, 11, Server), maps to 25 MITRE ATT&CK techniques (T1007, T1027.003, T1033), and is covered by 9 detection rules and 31 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 1DOUBLECUP Operation
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 31Indicators of compromise
Key facts for TL-2026-1847
- Threat ID
- TL-2026-1847
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- DOUBLECUP Operation
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- technology, software, enterprise-saas, cloud, manufacturing, retail, finance
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in
Malware and tooling: CountLoader, Ethereum Smart Contract: 0xe26c57b7fa8de030238b0a71b3d063397ac127d3, Polygon Smart Contract: 0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0, certutil - S0160
How DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in works
DOUBLECUP is a Russian loader-as-a-service (LaaS) that uses ClickFix social-engineering (fake CAPTCHA) to trick victims into running commands that extract malicious payloads from PNG images cached in their browser via steganography. It delivers CountLoader (Windows and macOS info-stealer) and DeviceManager RAT (Python-based Windows RAT using EtherHiding blockchain C2). Active campaigns target users of NetSuite, Odoo, HubSpot, and Salesforce with fake login page lures.
DOUBLECUP is a Russian loader-as-a-service operation first identified by SOCRadar's Threat Research Unit, active since early June 2026. The service provides cybercriminals with a Go-based Windows application for configuring malicious campaigns that combine ClickFix social engineering with steganographic payload concealment in browser-cached PNG images.
The attack chain begins when a victim visits a compromised website or fake login page impersonating NetSuite, Odoo, HubSpot, or Salesforce. DOUBLECUP registers the session, determines the victim's public IP address, and forces the browser to download and cache a PNG image containing a hidden payload concealed within its pixel data via steganography. The page then displays a fake CAPTCHA prompt instructing the victim to press Win+R, paste the command automatically copied to their clipboard, and execute it.
The executed command searches the browser cache for the PNG by exact file size and uses findstr or certutil to extract and execute the hidden first-stage payload. The first payload launches a fileless second-stage dropper that retrieves the victim's public IPv4 address to create a decryption key for the final encrypted payload. After verifying against a hardcoded SHA-256 hash, the dropper executes the final payload in memory without writing to disk.
DOUBLECUP delivers two primary payload families: CountLoader, a cross-platform info-stealer targeting both Windows and macOS (Intel and Apple Silicon), and DeviceManager, a previously undocumented modular Python-based Windows RAT that uses EtherHiding to resolve C2 server IP addresses from Ethereum or Polygon blockchain smart contracts. DeviceManager further evades detection by using DNS A and TXT records for bidirectional command and control communication.
The DOUBLECUP service infrastructure includes hosted steganographic PNG generation, session and signal endpoints, encryption key management, and automatic payload rebuilding. Commands are customized per browser (Chrome, Edge, Firefox, Brave, Opera) with corresponding cache directory paths. DeviceManager employs geo-fencing by avoiding data collection from CIS (Commonwealth of Independent States) countries, reinforcing the Russian attribution.
CountLoader collects system information, detects cryptocurrency wallet applications and browser extensions, checks for Signal Desktop installation, establishes persistence via scheduled tasks (Windows) or LaunchAgents (macOS), and downloads and executes MSI packages, PowerShell modules, and DLLs. DeviceManager collects machine GUID, disk identifier, user SID, hostname, username, OS version, architecture, installed antivirus products, and domain information, exfiltrating data via DNS tunneling over A and TXT record queries.
MITRE ATT&CK techniques used in TL-2026-1847
Discovery
T1007 System Service Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery; T1614.001 System Language Discovery
Defense Evasion
T1027.003 Steganography; T1036.003 Rename Legitimate Utilities; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1620 Reflective Code Loading
Persistence
T1053.005 Scheduled Task; T1543.001 Launch Agent; T1547.001 Registry Run Keys / Startup Folder
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.001 Malicious Link
Command and Control
T1071.001 Web Protocols; T1071.004 DNS; T1102.002 Bidirectional Communication
Initial Access
T1078 Valid Accounts; T1566.002 Spearphishing Link
stealth
Affected products and versions in DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in
- Microsoft — Windows (10, 11, Server)
Vulnerable versions: 10; 11; Server 2019; Server 2022 - Apple — macOS (Ventura, Sonoma, Sequoia)
Vulnerable versions: 13; 14; 15 - Google — Chrome Browser
Vulnerable versions: All versions - used as delivery vector - Mozilla — Firefox Browser
Vulnerable versions: All versions - used as delivery vector - Microsoft — Edge Browser
Vulnerable versions: All versions - used as delivery vector - Brave Software — Brave Browser
Vulnerable versions: All versions - used as delivery vector - Opera Software — Opera Browser
Vulnerable versions: All versions - used as delivery vector - Oracle — NetSuite
Vulnerable versions: Used as lure in phishing campaigns - HubSpot — HubSpot CRM
Vulnerable versions: Used as lure in phishing campaigns - Salesforce — Salesforce CRM
Vulnerable versions: Used as lure in phishing campaigns
Remediation for DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in
Immediate actions
- Block network access to 213.139.77.109 and associated DOUBLECUP infrastructure
- Block known CountLoader C2 domains at perimeter (globalsnn*-new.cc, *-bucket*.cc, memory-scanner.cc, hell*-kitty.cc)
- Deploy EDR detection rules for browser cache file access by findstr/certutil/powershell processes
- Implement user awareness training on fake CAPTCHA and Win+R copy-paste social engineering
- Monitor for unauthorized scheduled tasks mimicking Google updater names (GoogleTaskSystem*)
Workarounds
- Disable or restrict PowerShell execution policy for standard users on Windows endpoints
- Block outbound DNS TXT record queries to suspicious or unresolvable domains
- Restrict certutil.exe and findstr.exe execution via AppLocker or Windows Defender Application Control
- Enforce browser cache encryption and periodic cache clearing on managed endpoints
Longer-term hardening
- Deploy behavioral detection for fileless execution chains originating from browser cache directories
- Implement DNS tunneling detection (analysis of DNS TXT record queries for anomalous volume)
- Deploy steganographic payload detection via PNG pixel analysis on cached browser images
- Monitor blockchain RPC queries (Ethereum/Polygon eth_call to smart contracts) from endpoints
- Deploy YARA rules for steganographic PNG payloads in browser cache (%LOCALAPPDATA%\*\Cache\Cache_Data\*)
- Implement Sigma rules for browser cache smuggling payload extraction (processes reading cache dirs with read/carve verbs)
Timeline of DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in
- DOUBLECUP LaaS operational window: early June 2026 through present; active campaigns continue targeting enterprise SaaS users globally with evolving infrastructure and payload delivery mechanisms
- DOUBLECUP loader-as-a-service begins operations; SOCRadar Threat Research Unit detects initial activity and open directory at 213.139.77.109:9090 containing test files
- First observed fake CAPTCHA campaigns targeting enterprise SaaS platforms; compromised websites and fake login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce begin distributing ClickFix lures
- CountLoader (Windows info-stealer variant) confirmed being delivered via DOUBLECUP infrastructure; establishes persistence via scheduled tasks mimicking Google updater names
- DeviceManager RAT (Python-based Windows RAT) observed in active campaigns; uses EtherHiding technique to resolve C2 from Ethereum smart contracts and DNS A/TXT record tunneling for data exfiltration
- DOUBLECUP service expands browser targeting; API configuration endpoint customized to serve browser-specific extraction commands for Chrome, Edge, Firefox, Brave, and Opera
- CountLoader macOS variant deployed, compiled for both Intel and Apple Silicon architectures; uses LaunchAgent persistence and system_profiler/ioreg for host enumeration and VM detection
- DOUBLECUP licensing panel at 213.139.77.109 confirmed active; IP hosted by Ultahost (AS398256) with 98.4% VirusTotal-confirmed malicious rate on the ASN; expanded campaign toolkit features observed
- Fileless execution chain refined with IP-based decryption key derivation: second-stage dropper uses victim's public IPv4 address to create unique decryption key for final payload, verified against hardcoded SHA-256 hash before in-memory execution
- DeviceManager RAT observed rotating C2 addresses via Polygon blockchain smart contract (0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0); weekly C2 rotation cadence established using public Polygon RPC providers
- SOCRadar publishes full research report on DOUBLECUP; BleepingComputer publishes article detailing the threat including technical analysis, infrastructure details, and indicators of compromise
Sources cited for DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in
- New DOUBLECUP ClickFix service hides malware in browser cache images
- Sinkholing CountLoader: Insights into Its Recent Campaign
- EtherRAT SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons
- From Loader to Looter: ACR Stealer Rides on Upgraded CountLoader
- ClickFix Gets Creative: Malware Buried in Images
- Cache Smuggling: When a Picture Isn't a Thousand Words
- EtherRAT: Ethereum-based C2, EtherHiding, Powering Stealthy Malware Campaigns
- EtherRAT GitHub SEO and Ethereum C2
- ClickFix-Based Payload Delivery via Browser Cache Smuggling
- FTC Consumer Alert: Fake CAPTCHA Scams
- Sigma Detection Rule: Browser Cache Smuggling Payload Extraction
- ClickFix Browser Cache Smuggling (TL-2026-0127)
- ACR Stealer: Two Observed Intrusion Chains
Detection coverage for TL-2026-1847
As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1847 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1847
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.