# DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganography

> DOUBLECUP is a Russian loader-as-a-service (LaaS) that uses ClickFix social-engineering (fake CAPTCHA) to trick victims into running commands that extract malicious payloads from PNG images cached in their browser via steganography. It delivers CountLoader (Windows and macOS info-stealer) and DeviceManager RAT (Python-based Windows RAT using EtherHiding blockchain C2). Active campaigns target users of NetSuite, Odoo, HubSpot, and Salesforce with fake login page lures.

- **Published:** 2026-08-03T00:00:00Z
- **Last reviewed:** 2026-08-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1847
- **ID:** TL-2026-1847
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** DOUBLECUP Operation (Russia)
- **Detections:** 9 · **IOCs:** 31 (full data via the Threadlinqs MCP server — Purple tier)

## Description

DOUBLECUP is a Russian loader-as-a-service operation first identified by SOCRadar's Threat Research Unit, active since early June 2026. The service provides cybercriminals with a Go-based Windows application for configuring malicious campaigns that combine ClickFix social engineering with steganographic payload concealment in browser-cached PNG images.

The attack chain begins when a victim visits a compromised website or fake login page impersonating NetSuite, Odoo, HubSpot, or Salesforce. DOUBLECUP registers the session, determines the victim's public IP address, and forces the browser to download and cache a PNG image containing a hidden payload concealed within its pixel data via steganography. The page then displays a fake CAPTCHA prompt instructing the victim to press Win+R, paste the command automatically copied to their clipboard, and execute it.

The executed command searches the browser cache for the PNG by exact file size and uses findstr or certutil to extract and execute the hidden first-stage payload. The first payload launches a fileless second-stage dropper that retrieves the victim's public IPv4 address to create a decryption key for the final encrypted payload. After verifying against a hardcoded SHA-256 hash, the dropper executes the final payload in memory without writing to disk.

DOUBLECUP delivers two primary payload families: CountLoader, a cross-platform info-stealer targeting both Windows and macOS (Intel and Apple Silicon), and DeviceManager, a previously undocumented modular Python-based Windows RAT that uses EtherHiding to resolve C2 server IP addresses from Ethereum or Polygon blockchain smart contracts. DeviceManager further evades detection by using DNS A and TXT records for bidirectional command and control communication.

The DOUBLECUP service infrastructure includes hosted steganographic PNG generation, session and signal endpoints, encryption key management, and automatic payload rebuilding. Commands are customized per browser (Chrome, Edge, Firefox, Brave, Opera) with corresponding cache directory paths. DeviceManager employs geo-fencing by avoiding data collection from CIS (Commonwealth of Independent States) countries, reinforcing the Russian attribution.

CountLoader collects system information, detects cryptocurrency wallet applications and browser extensions, checks for Signal Desktop installation, establishes persistence via scheduled tasks (Windows) or LaunchAgents (macOS), and downloads and executes MSI packages, PowerShell modules, and DLLs. DeviceManager collects machine GUID, disk identifier, user SID, hostname, username, OS version, architecture, installed antivirus products, and domain information, exfiltrating data via DNS tunneling over A and TXT record queries.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1078 Valid Accounts
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1204.001 Malicious Link
- T1218.003 CMSTP
- T1218.005 Mshta
- T1053.005 Scheduled Task
- T1543.001 Launch Agent
- T1547.001 Registry Run Keys / Startup Folder
- T1027.003 Steganography
- T1140 Deobfuscate/Decode Files or Information
- T1055 Process Injection
- T1620 Reflective Code Loading
- T1497.001 System Checks
- T1036.003 Rename Legitimate Utilities
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1518.001 Security Software Discovery
- T1057 Process Discovery
- T1614.001 System Language Discovery
- T1007 System Service Discovery
- T1071.001 Web Protocols
- T1071.004 DNS
- T1102.002 Bidirectional Communication

## Sources

- [New DOUBLECUP ClickFix service hides malware in browser cache images](https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/)
- [Sinkholing CountLoader: Insights into Its Recent Campaign](https://www.mcafee.com/blogs/)
- [EtherRAT SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons](https://www.esentire.com/blog/etherrat-sys-info-module-c2-on-ethereum-etherhiding-target-selection-cdn-like-beacons)
- [From Loader to Looter: ACR Stealer Rides on Upgraded CountLoader](https://www.cyderes.com/howler-cell/acr-stealer-rides-on-upgraded-countloader)
- [ClickFix Gets Creative: Malware Buried in Images](https://www.huntress.com/blog/clickfix-malware-buried-in-images)
- [Cache Smuggling: When a Picture Isn't a Thousand Words](https://expel.com/blog/cache-smuggling-when-a-picture-isnt-a-thousand-words/)
- [EtherRAT: Ethereum-based C2, EtherHiding, Powering Stealthy Malware Campaigns](https://cybernoz.com/ethereum-based-etherrat-etherhiding-power-stealthy-malware-campaigns/)
- [EtherRAT GitHub SEO and Ethereum C2](https://lyrie.ai/research/research/2026-05-04-etherrat-github-seo-ethereum-c2)
- [ClickFix-Based Payload Delivery via Browser Cache Smuggling](https://cyhawk-africa.com/advisory/advisory-on-clickfix-based-payload-delivery-via-browser-cache-smuggling/)
- [FTC Consumer Alert: Fake CAPTCHA Scams](https://www.ftc.gov/news-events/news/consumer-alerts/2026/06/fake-captcha-scams)
- [Sigma Detection Rule: Browser Cache Smuggling Payload Extraction](https://github.com/SigmaHQ/sigma/pull/6078)
- [ClickFix Browser Cache Smuggling (TL-2026-0127)](https://threadlinqs.com/blog/TL-2026-0127-clickfix-cache-smuggling/)
- [ACR Stealer: Two Observed Intrusion Chains](https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1847
