Back to feed
Dev.to
Dev.to
8/4/2026
DOUBLECUP: ClickFix Loader-as-a-Service Restoring Fileless Payload from PNG in Browser Cache

DOUBLECUP: ClickFix Loader-as-a-Service Restoring Fileless Payload from PNG in Browser Cache

Short summary

DOUBLECUP is a Russian Loader-as-a-Service that uses fake CAPTCHA pages on spoofed CRM sites to inject clipboard commands, extracting malware stages hidden in browser-cache PNG files. The final payload is decrypted using the victim's public IP as key material and executed in memory, deploying CountLoader or DeviceManager RAT with persistence via Scheduled Tasks, WMI, or LaunchAgents. SOCs should watch for browser-to-PowerShell/certutil/findstr process chains, abnormal DNS A/TXT records, and blockchain RPC C2 traffic.

  • DOUBLECUP LaaS hides fileless payloads in browser-cache PNGs via fake CAPTCHA clipboard injection
  • CountLoader and DeviceManager RAT establish persistence and use Ethereum/Polygon smart contracts for C2
  • Detection requires monitoring abnormal parent-child process chains and blocking stego-image downloads

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more