DOUBLECUP is a Russian loader-as-a-service operation active since at least early June 2026 that supports ClickFix-style social-engineering campaigns. It is designed to help operators deliver malware by staging steganographic payloads inside PNG images that are forced into a victim’s browser cache, then tricking the victim into manually executing a browser-specific command copied to the clipboard via a fake CAPTCHA or verification prompt. Observed lure pages impersonated enterprise and CRM login portals including NetSuite, Odoo, HubSpot, and Salesforce.
The service provides customers with licensed tooling and campaign infrastructure, including a Go-based Windows client for configuring campaigns and generating frontend code for lure sites. DOUBLECUP operators host the steganographic images, manage victim sessions, issue encryption keys, and automatically rebuild payloads. The generated attack flow registers the victim session, identifies the browser, preloads the malicious PNG into cache, and presents execution instructions tailored for browsers such as Chrome, Edge, Firefox, Brave, and Opera.
The execution chain extracts hidden JavaScript, VBScript, or PowerShell from the cached PNG and launches a fileless second-stage dropper. DOUBLECUP uses environmental keying by deriving payload decryption material from the victim’s public IPv4 address, causing the final payload to decrypt correctly only on the intended host and complicating offline sandbox analysis. Reported implementations use a custom SHA-256 CTR-style stream cipher with XOR for in-memory payload decryption.
Observed payloads delivered through DOUBLECUP include updated Windows and macOS variants of CountLoader and a previously undocumented Windows remote access trojan named DeviceManager. CountLoader performs host profiling, searches for cryptocurrency wallet applications and browser extensions, checks for Signal Desktop, establishes persistence through scheduled tasks on Windows or LaunchAgents on macOS, and can download and execute additional payloads such as MSI packages, DLLs, PowerShell modules, and other files. DeviceManager is a modular Python-based RAT that gathers host and user metadata, avoids execution on systems using CIS-language locales, resolves command-and-control infrastructure through EtherHiding using Ethereum or Polygon smart contracts, and communicates over HTTP or DNS to receive commands, exfiltrate data, and download further payloads.
DOUBLECUP reflects the commercialization of ClickFix delivery tradecraft, combining social engineering, steganography, fileless staging, and anti-analysis measures to support post-compromise malware deployment across Windows and macOS environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Browser cache monitoring: Develop detection for PowerShell, VBScript, or JavaScript execution originating from browser cache directories... Clipboard-injection-to-execution detection: ... powershell[.]exe, cscript[.]exe, wscript[.]exe, or cmd[.]exe executing clipboard content shortly after.
ClickFix commands that, upon execution, search the browser cache for the PNG image and extract from it malicious JavaScript, VBScript, or PowerShell to launch the next-stage component.
ClickFix commands that, upon execution, search the browser cache for the PNG image and extract from it malicious JavaScript, VBScript, or PowerShell to launch the next-stage component.
The infection chain forces the victim’s browser to cache a steganographic PNG image containing hidden code. The copied command searches the browser cache, extracts the embedded code, and executes the first-stage payload.
The second stage operates as an obfuscated, fileless dropper that uses the victim’s public IP address to derive a cryptographic key and decrypt the final payload in memory.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivery service operating as a loader-as-a-service platform. It supports ClickFix campaigns by hosting steganographically embedded payloads in PNG images, managing sessions, issuing encryption keys, rebuilding payloads automatically, and generating browser-specific execution commands.
Russian Loader-as-a-Service used in ClickFix campaigns. It presents fake verification prompts, causes the browser to cache a steganographic PNG, extracts hidden code from that cache, and decrypts the final payload in memory using the victim's public IP address as part of the key.
A newly reported Russian loader-as-a-service used in ClickFix campaigns. It uses steganography and environmental keying to deliver payloads while evading detection.
Russian loader-as-a-service that uses ClickFix lures and steganographic PNGs cached in the victim's browser to stage and decrypt payloads in memory. It delivers follow-on malware including CountLoader and DeviceManager, uses environmental keying based on the victim's public IP address, and supports operator campaign management via licenses, a GUI client, and a Telegram bot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.