# QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410), Greatness AiTM/device-code PhaaS, EtherRAT blockchain C2

> QuoIntelligence's week 32 2026 snapshot (30 Jul - 5 Aug 2026) groups four active campaigns: the DOUBLECUP loader-as-a-service driving ClickFix lures that deliver CountLoader and DeviceManager RAT, UTA0533 exploiting SonicWall SMA 1000 zero-days CVE-2026-15409 and CVE-2026-15410 for root access, the Greatness PhaaS adding device-code phishing to Microsoft 365 AiTM, and a The Gentlemen ransomware affiliate running EtherRAT with C2 domains rotated through an Ethereum smart contract.

- **Published:** 2026-08-06T00:00:00Z
- **Last reviewed:** 2026-08-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2893
- **ID:** TL-2026-2893
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Actor:** The Gentlemen
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-15409, CVE-2026-15410

## Description

The QuoIntelligence snapshot (published 2026-08-06) is headline-only; technical detail below comes from the primary vendor and press reporting behind each headline.

DOUBLECUP: a Russian loader-as-a-service active since early June 2026 that supports ClickFix campaigns. Lure pages impersonating NetSuite, Odoo, HubSpot and Salesforce logins present a fake CAPTCHA/verification and copy a command to the clipboard. The command (findstr or certutil per reporting) extracts hidden code from a steganographic PNG that the victim's browser has cached; the final payload is decrypted in memory using the victim's public IPv4 address as part of the key (environmental keying), with a custom SHA-256 stream cipher, CIS locale checks and self-deletion. Payloads are an updated CountLoader (Windows PowerShell and macOS variants; wallet, extension and Signal Desktop checks; scheduled-task or LaunchAgent persistence; can fetch MSI, PowerShell and DLL payloads) and a previously undocumented Python-based DeviceManager RAT that resolves its C2 through blockchain smart contracts (EtherHiding) and uses DNS for tasking. A licensing panel open directory was seen at 213.139.77.109:9090 and a Telegram bot is used for key distribution.

UTA0533 / SonicWall SMA 1000: Volexity tracks UTA0533 as exploiting two zero-days since at least 2026-06-22, about three weeks before disclosure. CVE-2026-15409 (CVSS 10.0) is a pre-authentication /wsproxy bypass (SSRF) that yields an unauthenticated WebSocket tunnel to localhost services; CVE-2026-15410 (CVSS 7.2) is a path traversal in the ctrl-service remove_hotfix workflow giving root command execution. The actor abused CouchDB on loopback, then deployed ROOTRUN (setuid binary, /usr/bin/xzfind), KNUCKLEBALL (Python loader deploy_new.py that injects Java components into a legitimate SonicWall process), the open-source Suo5 HTTP proxy and ORANGETAIL (custom Behinder-like Java web shell, AES-128, required specific User-Agent 'SMA Connect Agent'). Persistence was via modified /etc/init.d/workplace and NGINX Unit config; tcpdump was used to capture unencrypted LDAP credentials. Attribution is unconfirmed; Volexity describes tradecraft as more consistent with state-sponsored activity. Rapid7 reported significant overlap and a public PoC exists; a secondary source reports INC Ransomware weaponizing the same chain. Fixed firmware: 12.4.3-03453 or 12.5.0-02835.

Greatness: a phishing-as-a-service platform (documented since 2023) now offers both AiTM token/cookie theft and OAuth device-code phishing against Microsoft 365, with iCloud, Yahoo and Google Workspace also targeted. ZeroBEC observed a RingCentral voicemail lure using a five-stage redirect chain with CAPTCHA gating and abuse of safe-sender exclusions; proxy IP 38.248.95.214 authenticated to a victim account more than two weeks after the lure, followed by Graph API enumeration, device registration for persistence and delayed malicious inbox rules.

EtherRAT / The Gentlemen: hunt.io (2026-08-04) documents a The Gentlemen ransomware affiliate deploying EtherRAT (Node.js implant, MSI installer) via ClickFix initial access discovered 2026-06-16. EtherRAT reads its C2 domain from an Ethereum smart contract (checked roughly every 5 minutes) through hardcoded public RPC endpoints, so each domain rotation is permanently recorded on-chain. The operator also used Sliver, Chisel, Ligolo-ng, Mimikatz, LSASS dumping, Potato-family privilege escalation, created accounts, disabled ESET services and moved laterally by SMB/scheduled-task MSI deployment.

Also listed in the snapshot: Pass-ta-key attacks, where malware already on a Windows endpoint abuses Chrome's TPM-backed identity key to hijack Google synced passkeys. The snapshot's item on Claude models attacking real systems during misconfigured evaluations and its geopolitical items are out of scope for this record.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1566.002 Spearphishing Link
- T1204.004 User Execution: Malicious Copy and Paste
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.006 Command and Scripting Interpreter: Python
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1505.003 Server Software Component: Web Shell
- T1098.005 Account Manipulation: Device Registration
- T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid
- T1027.003 Obfuscated Files or Information: Steganography
- T1055 Process Injection
- T1620 Reflective Code Loading
- T1685 Disable or Modify Tools
- T1218.007 System Binary Proxy Execution: Msiexec
- T1557 Adversary-in-the-Middle
- T1040 Network Sniffing
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1003.001 OS Credential Dumping: LSASS Memory
- T1102.001 Web Service: Dead Drop Resolver
- T1071.001 Application Layer Protocol: Web Protocols
- T1090 Proxy
- T1572 Protocol Tunneling

## Sources

- [Threat Intelligence Snapshot: Week 32, 2026 (QuoIntelligence)](https://quointelligence.eu/2026/08/threat-intelligence-snapshot-week-32-2026/)
- [The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 (hunt.io)](https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2)
- [SonicWall SMA Zero-Days Exploited (The Hacker News)](https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html)
- [CSA Research Note: UTA0533 Weeks-Long Espionage Chain in SonicWall SMA1000](https://labs.cloudsecurityalliance.org/research/csa-research-note-sonicwall-sma1000-uta0533-zeroday-20260725/)
- [Volexity blog archive: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation](https://www.volexity.com/blog/2026/07/17/)
- [DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT (The Hacker News)](https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html)
- [New DOUBLECUP ClickFix service hides malware in browser cache images (BleepingComputer)](https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/)
- [Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs (SOCRadar)](https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/)
- [Greatness PhaaS Adds Device Code Phishing (The Hacker News)](https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html)
- [New Pass-ta-key attacks let malware hijack Google synced passkeys (BleepingComputer)](https://bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys)
- [Rapid7 CVE-2026-15409 PoC](https://github.com/remmons-r7/rapid7-CVE-2026-15409)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2893
