HackerFeeds

CyberSecurity News

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

The Hacker News
· August 4, 2026

AI summary

A newly discovered Russian loader-as-a-service called DOUBLECUP is being used to deliver malware. It uses ClickFix lures to plant malicious PNG images in a victim's browser cache. The initial stage of the attack involves dropping a PNG image into the cache, from which hidden content is retrieved and executed. This ultimately leads to the delivery of two types of malware: CountLoader and a remote access trojan known as DeviceManager. The DeviceManager trojan has not been documented previously. The use of steganographic PNG images is a key part of the DOUBLECUP attack method.

Read the full article at The Hacker Newsthehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.