{"id":1117,"date":"2026-08-03T09:31:37","date_gmt":"2026-08-03T07:31:37","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=1117"},"modified":"2026-08-17T09:34:41","modified_gmt":"2026-08-17T07:34:41","slug":"new-doublecup-clickfix-service-hides-malware-in-browser-cache-images","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/08\/03\/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images\/","title":{"rendered":"New DOUBLECUP ClickFix service hides malware in browser cache images"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims&#8217; browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SOCRadar&#8217;s Threat Research Unit says DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The service handles much of the infrastructure required to conduct the attacks, including hosting the steganographic PNG images, managing session and signal endpoints, providing encryption keys, and automatically rebuilding payloads.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/08\/03\/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images\/\" target=\"_self\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images\/\">New DOUBLECUP ClickFix service hides malware in browser cache images<\/a><span class=\"screen-reader-text\">: New DOUBLECUP ClickFix service hides malware in browser cache images<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims&#8217; browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. SOCRadar&#8217;s Threat Research Unit says DOUBLECUP has operated since early June&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[72,9],"class_list":["post-1117","post","type-post","status-publish","format-standard","hentry","category-malware","tag-72","tag-russia"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=1117"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1117\/revisions"}],"predecessor-version":[{"id":1118,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1117\/revisions\/1118"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=1117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=1117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=1117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}