Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

New DOUBLECUP ClickFix service hides malware in browser cache images

Russian loader-as-a-service DOUBLECUP uses ClickFix lures and steganographic PNG payloads cached by victims' browsers to deliver malware on both Windows and macOS—a novel evasion chain SOCs should prepare for.

Summary written by editorial AI · Source link below

Filed by BleepingComputer1 min readRead at source ↗

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]

Editorial Analysis

Why it matters

The steganographic browser-cache technique evades conventional file and network inspection, requiring defenders to rethink where they look for payloads.

What to do

Update SOC playbooks to include browser-cache forensics and deploy IOCs for DOUBLECUP, CountLoader, and DeviceManager RAT.

Board brief

A new malware-delivery service hides attacks inside cached browser images, evading traditional security controls on both Windows and Mac systems.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at BleepingComputer

External link — opens at BleepingComputer in a new tab.

§
Continue with

More from the Threat Intel Desk