DOUBLECUP is a Russian loader-as-a-service platform used in ClickFix campaigns since at least early June 2026. It is designed to help operators build and run lure-driven malware delivery chains that impersonate business login portals and present fake verification or CAPTCHA prompts to trick victims into manually executing clipboard-delivered commands. Observed lures have impersonated enterprise SaaS and CRM brands including NetSuite, Odoo, HubSpot, and Salesforce.
The service provides licensed tooling and campaign infrastructure, including a Go-based Windows client for configuring campaigns and generating browser-specific delivery code. In observed operations, the lure page registers the victim session, identifies the browser, and forces a malicious PNG image into the browser cache. The copied command then searches the cache for that image, extracts appended or embedded script content using native utilities such as findstr or certutil, and executes a first-stage payload that launches a fileless second-stage dropper.
DOUBLECUP’s delivery chain is notable for combining browser-cache staging with environmental keying. The second stage derives a decryption key from the victim’s public IPv4 address and decrypts the final payload in memory using a custom stream-cipher scheme based on SHA-256 in CTR mode with XOR. This design helps ensure that payload decryption succeeds only on the intended host and can frustrate offline sandboxing and analysis on non-target networks.
Observed payloads delivered through DOUBLECUP include updated Windows and macOS variants of CountLoader and a previously undocumented Windows remote access trojan named DeviceManager. CountLoader performs host profiling, checks for cryptocurrency wallet applications and browser extensions, looks for Signal Desktop, establishes persistence through scheduled tasks on Windows or LaunchAgents on macOS, and can download and execute additional payloads such as MSI packages, DLLs, PowerShell modules, and other files. DeviceManager is a modular Python-based RAT that avoids execution on systems using CIS-language locales, collects host and user metadata, executes commands and scripts, downloads additional payloads, and communicates over HTTP or DNS. It also uses EtherHiding techniques, retrieving command-and-control information from Ethereum or Polygon smart contracts.
DOUBLECUP has been linked in reporting to the threat actor name Rognar and to operational infrastructure that included Telegram-based notifications and campaign management. The platform targets Windows primarily, with observed downstream delivery to both Windows and macOS systems through CountLoader.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Browser cache monitoring: Develop detection for PowerShell, VBScript, or JavaScript execution originating from browser cache directories... Clipboard-injection-to-execution detection: ... powershell[.]exe, cscript[.]exe, wscript[.]exe, or cmd[.]exe executing clipboard content shortly after.
That makes that you don't need a custom payload extractor, you can just use the FINDSTR command ... to extract the script: And then pipe it into the PowerShell interpreter.
ClickFix commands that, upon execution, search the browser cache for the PNG image and extract from it malicious JavaScript, VBScript, or PowerShell to launch the next-stage component.
It doesn't use real steganography: You can see the PowerShell payload as cleartext: it has not been encoded into the pixels of the image. | New malware that uses steganography always gets my attention... It doesn't use real steganography... it's just appended after the PNG file
The second stage operates as an obfuscated, fileless dropper that uses the victim’s public IP address to derive a cryptographic key and decrypt the final payload in memory.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DOUBLECUP is described as malware that hides a PowerShell payload by appending it after a PNG file rather than using true steganography. The payload can be extracted with FINDSTR using a unique identifier and then piped into PowerShell for execution.
Malware delivery service operating as a loader-as-a-service platform. It supports ClickFix campaigns by hosting steganographically embedded payloads in PNG images, managing sessions, issuing encryption keys, rebuilding payloads automatically, and generating browser-specific execution commands.
Russian Loader-as-a-Service used in ClickFix campaigns. It presents fake verification prompts, causes the browser to cache a steganographic PNG, extracts hidden code from that cache, and decrypts the final payload in memory using the victim's public IP address as part of the key.
A newly reported Russian loader-as-a-service used in ClickFix campaigns. It uses steganography and environmental keying to deliver payloads while evading detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.