Dev.to
8/4/2026

DOUBLECUP: ClickFix Loader-as-a-Service Restoring Fileless Payload from PNG in Browser Cache
Short summary
DOUBLECUP is a Russian Loader-as-a-Service that uses fake CAPTCHA pages on spoofed CRM sites to inject clipboard commands, extracting malware stages hidden in browser-cache PNG files. The final payload is decrypted using the victim's public IP as key material and executed in memory, deploying CountLoader or DeviceManager RAT with persistence via Scheduled Tasks, WMI, or LaunchAgents. SOCs should watch for browser-to-PowerShell/certutil/findstr process chains, abnormal DNS A/TXT records, and blockchain RPC C2 traffic.
- •DOUBLECUP LaaS hides fileless payloads in browser-cache PNGs via fake CAPTCHA clipboard injection
- •CountLoader and DeviceManager RAT establish persistence and use Ethereum/Polygon smart contracts for C2
- •Detection requires monitoring abnormal parent-child process chains and blocking stego-image downloads
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



