DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganography — Threadlinqs Intelligence
As of 2026-08-03, DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganography is a high-severity malware threat attributed to DOUBLECUP Operation (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1847 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: DOUBLECUP Operation · Russia · FINANCIAL
DOUBLECUP is a Russian loader-as-a-service (LaaS) that uses ClickFix social-engineering (fake CAPTCHA) to trick victims into running commands that extract malicious payloads from PNG images cached in
DOUBLECUP is a Russian loader-as-a-service operation first identified by SOCRadar's Threat Research Unit, active since early June 2026. The service provides cybercriminals with a Go-based Windows application for configuring malicious campaigns that combine ClickFix social engineering with steganographic payload concealment in browser-cached PNG images.
The attack chain begins when a victim visits a compromised website or fake login page impersonating NetSuite, Odoo, HubSpot, or Salesforce. DOUBLECUP registers the session, determines the victim's public IP address, and forces the browser to download and cache a PNG image containing a hidden payload concealed within its pixel data via steganography. The page then displays a fake CAPTCHA prompt instructing the victim to press Win+R, paste the command automatically copied to their clipboard, and execute it.
The executed command searches the browser cache for the PNG by exact file size and uses findstr or certutil to extract and execute the hidden first-stage payload. The first payload launches a fileless second-stage dropper that retrieves the victim's public IPv4 address to create a decryption key for the final encrypted payload. After verifying against a hardcoded SHA-256 hash, the dropper executes the final payload in memory without writing to disk.
DOUBLECUP delivers two primary payload families: CountLoader, a cross-platform info-stealer targeting both Windows and macOS (Intel and Apple Silicon), and DeviceManager, a previously undocumented modular Python-based Windows RAT that uses EtherHiding to resolve C2 server IP addresses from Ethereum or Polygon blockchain smart contracts. DeviceManager further evades detection by using DNS A and TXT records for bidirectional command and control communication.
The DOUBLECUP service infrastructure includes hosted steganographic PNG generation, session and signal endpoints, encryption key management, and automatic payload rebuilding. Commands are customized per browser (Chrome, Edge, Firefox, Brave, Opera) with corresponding cache directory paths. DeviceManager employs geo-fencing by avoiding data collection from CIS (Commonwealth of Independent States) countries, reinforcing the Russian attribution.
CountLoader collects system information, detects cryptocurrency wallet applications and browser extensions, checks for Signal Desktop installation, establishes persistence via scheduled tasks (Windows) or LaunchAgents (macOS), and downloads and executes MSI packages, PowerShell modules, and DLLs. DeviceManager collects machine GUID, disk identifier, user SID, hostname, username, OS version, architecture, installed antivirus products, and domain information, exfiltrating data via DNS tunneling over A and TXT record queries.
Target sectors: technology, software, enterprise-saas, cloud, manufacturing, retail, finance
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.002, T1078, T1059.001, T1059.003, T1204.001, T1218.003, T1218.005, T1053.005, T1543.001, T1547.001