A new Russian loader-as-a-service called DOUBLECUP uses ClickFix lures to hide malware in browser cache PNGs, delivering CountLoader and the DeviceManager RAT.
There's a new threat making the rounds, and it's sneakier than most. It's called DOUBLECUP, a Russian loader-as-a-service (LaaS) that's been using ClickFix lures to plant malicious PNG images right in your browser's cache. From there, it delivers two nasty payloads: CountLoader and a previously unknown remote access trojan (RAT) called DeviceManager.
If that sounds technical, don't worry—I'll break it down in plain English. The bottom line is this: cybercriminals are getting more creative about hiding their attacks in plain sight. And if you're not paying attention, you could easily become their next victim.
### What Exactly Is DOUBLECUP?
DOUBLECUP isn't a single piece of malware. It's a service—a loader-as-a-service, to be precise. Think of it like a delivery service for bad guys. They pay a fee, and DOUBLECUP handles the dirty work of getting malware onto victims' machines. It's a business model, and unfortunately, it's thriving.
The key innovation here is how it hides its payload. Instead of sending a suspicious executable or a zip file, it uses steganography—the art of hiding secret data inside innocent-looking files. In this case, the innocent-looking file is a PNG image.
### The ClickFix Lure: How It Starts
ClickFix is a social engineering technique that's been gaining traction. It works by presenting you with a fake error message or a captcha that asks you to "fix" a problem. The fix usually involves copying and pasting a command into your terminal or command prompt.
Here's the kicker: that command isn't fixing anything. It's downloading and executing malware. And because you're the one running the command, it often bypasses security software that's looking for suspicious behavior.
With DOUBLECUP, the ClickFix lure is just the beginning. Once you fall for it, the first stage drops a steganographic PNG image into your browser's cache. That's the clever part—the image sits in a place where most security tools aren't looking.
### How the PNG Attack Works
Your browser cache is designed to store images, scripts, and other elements to speed up your browsing experience. It's not something you typically inspect. And that's exactly why attackers love it.
Here's the step-by-step breakdown:
- The ClickFix lure tricks you into running a command.
- That command downloads a PNG image and stores it in your browser's cache.
- The image looks completely normal—a photo, a graphic, whatever.
- But hidden inside the image's pixel data is a second stage of the attack.
- The malware retrieves that hidden content and executes it.
It's like receiving a postcard with a secret message written in invisible ink. You see the picture, but the real message is hidden beneath the surface.
### Meet CountLoader and DeviceManager
Once the hidden content is extracted, DOUBLECUP delivers its payloads. The first is CountLoader, a known loader that's been around for a while. It's used to drop additional malware, often banking trojans or info stealers.
The second payload is more interesting: DeviceManager. This is a previously undocumented RAT, which means it's brand new to researchers. A RAT gives attackers remote control over your computer. They can see your screen, log your keystrokes, steal your files, and even use your webcam.
Having a RAT on your system is about as bad as it gets. It's like handing the keys to your house to a stranger and letting them move in.
### Why This Matters for You
You might be thinking, "I'm careful online. This won't happen to me." But here's the thing: ClickFix lures are designed to look legitimate. They appear in fake tech support pages, phishing emails, and even malicious ads. All it takes is one moment of distraction.
And the use of browser cache is a reminder that attackers are always looking for new hiding spots. Traditional antivirus might scan downloads and email attachments, but it's less likely to scrutinize cached images.
### How to Protect Yourself
So what can you do? Here are a few practical steps:
- **Be skeptical of copy-paste commands.** If a website tells you to paste something into your terminal, stop. Legitimate sites never ask you to do that.
- **Keep your software updated.** Patches fix vulnerabilities that attackers exploit.
- **Use a reputable security suite.** Make sure it includes web protection and behavior monitoring.
- **Clear your browser cache regularly.** It won't stop the attack, but it removes the hiding spot after the fact.
- **Think before you click.** If something feels off, it probably is.
The bottom line: DOUBLECUP is a reminder that cyber threats are evolving. The good news is that awareness is your best defense. Now that you know how this attack works, you're one step ahead of the bad guys.