A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
"The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second stage," SOCRadar said in a technical report. "This second stage decrypts the final payload in memory via a custom SHA-256 stream cipher in Counter (CTR) mode along with bitwise XOR using the victim's public IP address as the cryptographic key."
Payloads delivered via the loader service include CountLoader, with variants for both Windows and macOS, and DeviceManager, which utilizes EtherHiding to resolve its command-and-control (C2) infrastructure and communicate with the server over HTTP or DNS tunneling.
The service is assessed to be active since early June 2026, with the core developers providing operators with licenses and a client agent to help create campaigns and load payloads by embedding the required code in their ClickFix landing pages. Each license comes with a unique key and contains metadata including the client's IP address, active days, label, and version. Multiple campaigns can be orchestrated per license.







