CyberSecurity News
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
AI summary
A newly discovered Russian loader-as-a-service called DOUBLECUP is being used to deliver malware. It uses ClickFix lures to plant malicious PNG images in a victim's browser cache. The initial stage of the attack involves dropping a PNG image into the cache, from which hidden content is retrieved and executed. This ultimately leads to the delivery of two types of malware: CountLoader and a remote access trojan known as DeviceManager. The DeviceManager trojan has not been documented previously. The use of steganographic PNG images is a key part of the DOUBLECUP attack method.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

