New Russian 'DOUBLECUP' Malware Service Hides Malicious Code in Cached Images
Security researchers have uncovered a new malware delivery service called DOUBLECUP, operated as a 'loader-as-a-service' by Russian-speaking cybercriminals. The attack begins with a technique known as ClickFix, where victims are tricked into copying and running commands themselves, often after being shown a fake error message or verification prompt on a compromised or malicious website.
Once triggered, DOUBLECUP secretly stores a specially crafted PNG image in the victim's browser cache. This image looks harmless but contains hidden malicious code using a technique called steganography. The malware then extracts and runs this hidden code, ultimately installing two payloads: CountLoader, a known malware loader, and DeviceManager, a previously undocumented remote access trojan (RAT) that gives attackers ongoing control over infected devices.
Because this attack relies on tricking users into running commands themselves rather than exploiting a software vulnerability, traditional antivirus tools may not immediately flag it. This makes staff awareness and cautious browsing habits especially important for small businesses.