LIVEΒ·Tuesday, August 4, 2026
SkylineWire Logo

SkylineWire

Global News & Market Intelligence Β· Verified from Official Dispatches

Editions:
Home
LIVEMARKETS:
S&P 500 5,640.20 (+0.45% β–²)|NASDAQ 17,855.10 (+0.62% β–²)|BRENT CRUDE $82.40 (-0.85% β–Ό)|SAF FUEL $2,140/t (+1.2% β–²)
S&P 500 5,640.20 (+0.45% β–²)|NASDAQ 17,855.10 (+0.62% β–²)|BRENT CRUDE $82.40 (-0.85% β–Ό)|SAF FUEL $2,140/t (+1.2% β–²)
BreakingDeveloping StoryUpdated 3h agoβœ“ Verified Reporting
Cybersecurity· 🌍 Global

DOUBLECUP Malware Campaign Deploys DeviceManager RAT via ClickFix

A new Russian loader-as-a-service, DOUBLECUP, is distributing CountLoader and the new DeviceManager RAT by exploiting browser cache mechanisms via ClickFix lures.

By Skyline Wire Newsroom Β· Published August 4, 2026 at 9:03 AMSource: The Hacker News Β· Verified Reporting

Key Story Metrics & Context

Industry Sector:Cybersecurity
Companies Impacted:The Hacker News
Geographic Scale:Russia πŸ‡·πŸ‡Ί
Reporting Status:βœ“ Multi-Source Verified
DOUBLECUP Malware Campaign Deploys DeviceManager RAT via ClickFix

Executive Brief & Verified Analysis

βœ“ OFFICIAL SOURCES REVIEWED

Executive Summary

A new Russian loader-as-a-service, DOUBLECUP, is distributing CountLoader and the new DeviceManager RAT by exploiting browser cache mechanisms via ClickFix lures.

Why This Matters

Key strategic implication: DOUBLECUP operates as a Russian loader-as-a-service (LaaS) platform.

Market Impact

Verified for The Hacker News. Primary market adjustment vector.

Source Verification

Cross-referenced across regulatory dispatches, official press releases, and verified wire filings.

Strategic Implications

  • βœ“DOUBLECUP operates as a Russian loader-as-a-service (LaaS) platform.
  • βœ“The campaign uses steganography by hiding malicious code inside PNG image files.
  • βœ“The process utilizes the browser's cache as a staging area to avoid detection.
  • βœ“Two main payloads identified are CountLoader and the undocumented DeviceManager RAT.

A sophisticated Russian loader-as-a-service (LaaS) operation known as DOUBLECUP is actively targeting systems by utilizing ClickFix lures to initiate a multi-stage infection process. According to The Hacker News, this campaign leverages cached PNG files to bypass standard security filters, eventually dropping the CountLoader payload and a previously undocumented remote access trojan (RAT) identified as DeviceManager.

The attack sequence relies on steganography to conceal malicious code within image files. Once a victim interacts with a ClickFix-based prompt, the system is coerced into downloading a PNG file directly into the browser's local cache. From there, the loader extracts hidden instructions from the image data to trigger the subsequent infection phases. The ultimate objective of this operation is the establishment of persistent unauthorized access through the DeviceManager RAT.

Infection Mechanism Overview

ComponentFunction
DOUBLECUPLoader-as-a-Service (LaaS) framework
ClickFixInitial lure mechanism for user interaction
PNG CacheDelivery vehicle for steganographic payloads
CountLoaderSecondary stage loader
DeviceManagerUndocumented remote access trojan (RAT)

Security researchers have noted that the use of cached image files represents an evolving tactic in the LaaS market, aimed at circumventing endpoint detection and response (EDR) solutions that may be configured to inspect standard executable downloads but overlook browser-cached resources. This method of obfuscation allows the threat actors to maintain a low profile during the initial ingress of the malware.

Why It Matters

The emergence of DOUBLECUP highlights a shift toward more complex, multi-layered distribution models in the cyber-mercenary ecosystem. By decoupling the initial lure (ClickFix) from the final payload (DeviceManager) and utilizing browser cache as a temporary staging ground, threat actors are forcing security providers to rethink how they monitor browser-side file system interactions. This trend suggests that attackers are increasingly moving away from simple malicious attachments toward 'living-off-the-web' tactics that exploit standard browser functionality, making it significantly harder for traditional signature-based detection systems to identify threats before execution occurs.

Expected Next Steps

  • 1Security vendors likely to update EDR detection rules for browser cache anomalies.
  • 2Further research expected on the attribution of the DOUBLECUP threat group.
  • 3Potential discovery of additional payloads linked to the DOUBLECUP infrastructure.

Frequently Asked Questions

DOUBLECUP is a Russian loader-as-a-service (LaaS) that distributes malicious payloads by exploiting browser-based lures.

The operation currently delivers CountLoader and an undocumented remote access trojan known as DeviceManager.

The attack uses ClickFix lures to drop a steganographic PNG file into the browser cache, which then executes hidden instructions to download and run the malware.

Source Transparency & Verified Dispatches

βœ“ Verified Primary Data
βœ“
The Hacker NewsπŸ’Ό Corporate Dispatch
Source β†—

Reader Discussion & Insights

Leave a Comment

Loading discussion thread...

Get Breaking Global Intel in Your Inbox

Subscribe to the Skyline Wire AI Daily Briefing. Direct insights across Aviation, Tech, EVs, and Markets.

Original announcement link: The Hacker News

cybersecuritymalwaredoublecupratthreat-intelligence
doublecup malwaredevicemanager ratcountloaderclickfix luresteganography malwareloader-as-a-servicecybersecurity newsbrowser cache malware