DeviceManager is a modular Python-based Windows remote access trojan associated with malware delivery through the DOUBLECUP loader-as-a-service ecosystem. It has been observed as a later-stage payload in ClickFix-style intrusion chains that use fake business login pages and CAPTCHA-themed social engineering to induce victims to execute clipboard-delivered commands, after which staged code extracts and launches the malware chain.
The malware is designed for remote command execution and follow-on payload delivery. Reported functionality includes collecting host and user metadata such as hostname, operating system details, architecture, domain information, security product presence, machine identifiers, and user identifiers. It can receive commands, execute shell commands through the Windows command interpreter, run PowerShell and Python scripts, download additional payloads, and return execution results to its operators.
A notable feature of DeviceManager is its use of EtherHiding-style command-and-control resolution. Instead of relying solely on static infrastructure, it retrieves current command-and-control information from Ethereum or Polygon smart contracts, then communicates over HTTP or via DNS records, including use of DNS-based command-and-control mechanisms. This design complicates infrastructure disruption and tracking.
DeviceManager also includes regional evasion logic: it checks system language or locale settings and aborts execution on systems associated with CIS countries. It has been described as being packaged for execution with an embedded Python environment and delivered in installer form in at least some observed cases. High-confidence reporting supports its classification as a Windows RAT used for post-compromise control, reconnaissance, payload retrieval, and defense evasion within socially engineered malware campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
One of the malware families propagated via this method is an updated Windows and macOS version of CountLoader, which comes with new capabilities to establish persistence using scheduled tasks
с помощью findstr или certutil извлекает из изображения скрытый JavaScript, VBScript или PowerShell-код, который запускает дроппер второго этапа.
скрытый JavaScript, VBScript или PowerShell-код... Также этот загрузчик способен скачивать и запускать MSI-пакеты, DLL, PowerShell-модули... вредонос способен ... запускать скрипты PowerShell
Отмечается, что вредонос способен выполнять команды через cmd.exe
с помощью findstr или certutil извлекает из изображения скрытый JavaScript, VBScript или PowerShell-код
с помощью findstr или certutil извлекает из изображения скрытый JavaScript, VBScript или PowerShell-код
Для расшифровки финального пейлоада используется публичный IPv4-адрес жертвы: на его основе формируется ключ для кастомного потокового шифра на базе SHA-256 в режиме CTR с XOR.
скрывая вредоносный код в PNG-изображениях... хостит картинки со скрытыми при помощи стеганографии пейлоадами
Затем RAT использует HTTP или DNS-записи A и TXT для отправки данных, получения команд и загрузки новых пейлоадов.
RAT использует HTTP ... для отправки данных, получения команд и загрузки новых пейлоадов.
RAT использует HTTP или DNS-записи A и TXT для отправки данных, получения команд и загрузки новых пейлоадов.
The second payload delivered via the DOUBLECUP infrastructure is a modular Python-based RAT codenamed DeviceManager that utilizes the blockchain as a dead drop resolver to fetch the C2 server details, a technique known as EtherHiding.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously unknown modular Python RAT for Windows. It self-deletes if it detects CIS-language locales, collects host and user telemetry, resolves C2 via EtherHiding using Ethereum or Polygon smart contracts, and uses HTTP or DNS A/TXT records for command-and-control, data exfiltration, and payload retrieval. It can execute cmd.exe commands and run PowerShell and Python scripts.
A previously undocumented modular Python-based Windows RAT delivered through an Inno Setup installer and executed through an embedded Python environment without showing a console window. It provides persistence, system reconnaissance, command execution, payload delivery, and resilient command-and-control, and uses DNS tunneling for C2.
Previously undocumented modular Python-based RAT distributed via a Delphi-compiled Inno Setup installer. It resolves active C2 nodes through Ethereum/Polygon smart contracts using EtherHiding, avoids CIS-language systems, collects device information, exfiltrates data, polls for tasks, downloads payloads, and executes PowerShell, Python, and cmd.exe commands.
Previously undocumented modular Python-based Windows RAT delivered by DOUBLECUP. It gathers host and domain information outside CIS countries, uses EtherHiding via Ethereum or Polygon smart contracts to resolve C2 infrastructure, and uses DNS A and TXT records for command retrieval, payload download, exfiltration, and command output return.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.