Article analysis

THThe Hacker News
2w ago
TechCybersecurityMalware

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second

Confidence0%
Tilt0%

Skim this article about "DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT": 3 key takeaways and more.

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

skim AI Analysis | The Hacker News

The Hacker News on DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT: skim's analysis surfaces 3 key takeaways. DOUBLECUP, a Russian LaaS, uses ClickFix lures to deliver malware via steganographic PNGs. Read the takeaways in seconds, then decide whether the full article is worth your time.

Category: Tech. News article analyzed by skim.

Summary

DOUBLECUP, a Russian LaaS, uses ClickFix lures to deliver malware via steganographic PNGs. It deploys CountLoader and DeviceManager RAT, employing techniques like environmental keying and blockchain for C2 resolution. The service is active since June 2026, offering licenses and client agents for campaign creation.

Key Takeaways

  1. A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
  2. The service is assessed to be active since early June 2026, with the core developers providing operators with licenses and a client agent to help create campaigns and load payloads by embedding the required code in their ClickFix landing pages.
  3. The primary objective of CountLoader is to connect to a C2 server, gather system metadata and exfiltrate it, and await further tasks from the operator, allowing it to run secondary executables, DLLs, MSI, or HTML Application (HTA) files, download a compressed archive, extract its contents, and run the main binary present within the extracted folder, and clean up persistence mechanisms likely to erase forensic evidence.

Statement Breakdown

  • Claimed Facts: 70% of statements the article presents as facts
  • Opinions: 20% of statements classified as editorial or subjective
  • Claims: 10% of statements surfaced for additional reader evaluation

Credibility & Bias Reasoning

Credibility assessment: The article presents detailed technical analysis of malware, citing specific techniques and tools. It attributes findings to a cybersecurity firm, enhancing its credibility. The information is presented factually, with clear explanations of complex processes.

Bias assessment: Technical Security Reporting. The article focuses on the technical aspects of malware operations and threat actor methodologies. Its primary goal is to inform about cybersecurity threats and the methods used to detect and analyze them.

Note: This article provides a deep technical dive into malware operations. Readers should approach the information with an understanding of cybersecurity concepts and potential threat actor motivations.

Credibility flag: Technical Analysis

Claimed Facts (10)

  • This describes a specific technical step in the malware's execution chain, attributed to a cybersecurity firm.
  • This provides a technical detail about the decryption process used by the malware.
  • This lists the specific malware payloads delivered by DOUBLECUP and their communication methods.
  • This explains how the cybersecurity firm discovered the DOUBLECUP infrastructure.
  • This describes the functionalities of the DOUBLECUP operator client.
  • This provides a specific technical detail about the configuration endpoint used by DOUBLECUP.
  • This details the information retrieved from the configuration endpoint.
  • This identifies a specific tool used for communication and tracking within the DOUBLECUP operation.
  • This describes the social engineering tactics and initial infection vector used by DOUBLECUP.
  • This explains a specific anti-analysis technique used by the malware.

Opinions (5)

  • This is an assessment of the significance and impact of DOUBLECUP on threat actor capabilities.
  • This is an interpretation of the malware's design principles and effectiveness.
  • This is an analysis of how the malware achieves evasion and resilient C2 infrastructure.
  • This is an interpretation of a specific feature's status within the CountLoader malware.
  • This statement outlines the intended purpose and broad capabilities of the CountLoader malware.

Claims (5)

  • The term 'suspicious' is subjective and lacks concrete evidence within the text to support the claim of the VS Code extension being malicious.
  • While likely true in a malware operation, the article doesn't provide direct evidence of this notification occurring, making it an inferred claim.
  • The claim of 'extensive device information' is vague and not quantified, making it a broad assertion.
  • While plausible, the article doesn't provide specific examples or evidence of these commands being executed in a way that would be considered a dubious claim without further context.
  • The claim of 'self-deletion' is a strong assertion that, while possible, would require more direct evidence of the routine being successfully and completely executed.

Key Sources

  • The Hacker News — Cybersecurity News Outlet
  • SOCRadar — Cybersecurity Firm

This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.

skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 4th August 2026.