Threat Intelligence

New Russian 'DOUBLECUP' Malware Service Hides Malicious Code in Cached Images

The Hacker News · 4 Aug 2026
Key Takeaway Train staff to never copy-paste and run commands from websites or pop-ups claiming to 'fix' an error, as this is a common trick used to install hidden malware.

Security researchers have uncovered a new malware delivery service called DOUBLECUP, operated as a 'loader-as-a-service' by Russian-speaking cybercriminals. The attack begins with a technique known as ClickFix, where victims are tricked into copying and running commands themselves, often after being shown a fake error message or verification prompt on a compromised or malicious website.

Once triggered, DOUBLECUP secretly stores a specially crafted PNG image in the victim's browser cache. This image looks harmless but contains hidden malicious code using a technique called steganography. The malware then extracts and runs this hidden code, ultimately installing two payloads: CountLoader, a known malware loader, and DeviceManager, a previously undocumented remote access trojan (RAT) that gives attackers ongoing control over infected devices.

Because this attack relies on tricking users into running commands themselves rather than exploiting a software vulnerability, traditional antivirus tools may not immediately flag it. This makes staff awareness and cautious browsing habits especially important for small businesses.

malware phishing remote access trojan

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.