DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the DeviceManager RAT in memory.

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to…

DOUBLECUP: ClickFix Loader-as-a-Service Restoring Fileless Payload from PNG in Browser...