DOUBLECUP ClickFix service hides malware in browser-cached PNG images to infect Windows and macOS devices

Researchers say a new loader-for-hire service called DOUBLECUP is helping attackers infect people who visit fake login and CAPTCHA pages. The service, active since early June 2026, uses ClickFix prompts to trick victims into running clipboard-copied commands that pull hidden payloads from PNG images stored in browser cache. SOCRadar says campaigns impersonated NetSuite, Odoo, HubSpot, and Salesforce, delivering CountLoader on Windows and macOS and a newly documented Windows remote-access trojan called DeviceManager.
Why it matters: This matters because it turns ordinary web visits into malware setup pages that can fool users on both PCs and Macs without a software vulnerability. Organizations should warn users not to paste commands from browser prompts, watch for fake CAPTCHA/login pages, and hunt for CountLoader or DeviceManager activity.

Sources

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
SecurityWeek News 2026.08.07 83% relevant
This source adds that DoubleCup has been observed delivering CountLoader and DeviceManager RATs, and notes the campaign timing and use of steganography and environmental keying in ClickFix attacks.
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
info@thehackernews.com (The Hacker News) 2026.08.04 97% relevant
This article appears to report on the same DOUBLECUP malware-delivery operation, adding specific payload details including CountLoader and DeviceManager RAT and describing the use of ClickFix lures and browser-cached PNG files as part of the infection chain.
New DOUBLECUP ClickFix service hides malware in browser cache images
Lawrence Abrams 2026.08.03 100% relevant
This article establishes a distinct story about the DOUBLECUP malware-delivery service, its ClickFix-based attack chain, and the specific malware families it is distributing.
← Back to all stories