Find notable cyber news and cases, enriched with sources, timelines, and signals.

DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity

Malware Activity
First reported
Last updated
Happening score
H score 22
2 unique sources, 2 articles

Summary

Hide ▲

DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoader and a previously undocumented DeviceManager RAT. SOCRadar says the service provides licenses, a client agent, session and signal endpoints, encryption keys, and campaign-building tooling, while operators host lure sites and add the generated code. Observed campaigns used fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce. The payload chain adds persistence, system collection, and C2 channels, including EtherHiding, HTTP, and DNS tunneling.

Related Happenings

ClickFix macOS Terminal-command lure campaign

Campaign
H score42 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

About this happening: The ClickFix campaign is pushing macOS users to run a Terminal command, creating a live path to credential theft and crypto diversion. The lure arrives through email...

DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS

Threat Actor Meta
H score28 First: 03.08.2026 23:01 Last: 03.08.2026 23:01 Sources 1

How related: DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.

About this happening: DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...

DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages

Campaign
H score39 First: 03.08.2026 23:01 Last: 03.08.2026 23:01 Sources 1

How related: SOCRadar says it observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with the malicious code loaded through embedded iframes.

About this happening: The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...

Famous Chollima ClickFake Interview recruitment scam campaign

Campaign
H score34 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

About this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

Timeline

  1. 03.08.2026 23:01 3 articles · 3d ago

    DOUBLECUP ClickFix service hides malware in browser-cached PNG images

    Initial Disclosure

    SOCRadar reports a Russian loader-as-a-service named DOUBLECUP, operating since early June 2026, that supplies customers with licenses and a Go-based Windows tool for building ClickFix campaigns. The service hosts steganographic PNG images, manages session and signal endpoints, provides encryption keys, and automates payload rebuilding, while customers host the lure sites and add the generated code. Observed campaigns used fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce to deliver CountLoader to Windows and macOS and a DeviceManager RAT to Windows.

    Show sources