DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor Meta
Summary
Hide ▲
Show ▼
DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplies licenses, a Go-based Windows builder/client, and backend functions that generate campaign code, manage steganographic PNG delivery, and support operators who embed the required code in their ClickFix landing pages. Campaigns tied to the service have impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages and delivered CountLoader for Windows and macOS plus a DeviceManager RAT for Windows. The service lowers the barrier for browser-based malware delivery by combining cache-based staging, operator tooling, and EtherHiding-backed C2 handling.
Related Happenings
DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages
Campaign
H score39
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
How related:
SOCRadar says it observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with the malicious code loaded through embedded iframes.
About this happening:
The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...
DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages
CampaignHow related: SOCRadar says it observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with the malicious code loaded through embedded iframes.
About this happening: The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware Activity
H score22
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
How related:
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
About this happening:
DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware ActivityHow related: A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
About this happening: DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
OnyxC2 stealer remote-access and credential-theft activity
Malware Activity
H score23
First: 11.06.2026 16:00
Last: 11.06.2026 16:00
Sources 1
About this happening:
The OnyxC2 stealer has expanded into remote-access and persistence-enabled credential theft, giving buyers a way to harvest browser, extension, wallet, and business-app da...
OnyxC2 stealer remote-access and credential-theft activity
Malware ActivityAbout this happening: The OnyxC2 stealer has expanded into remote-access and persistence-enabled credential theft, giving buyers a way to harvest browser, extension, wallet, and business-app da...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware Activity
H score29
First: 01.04.2026 16:30
Last: 01.04.2026 16:30
Sources 1
About this happening:
The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware ActivityAbout this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Timeline
-
03.08.2026 23:01 3 articles · 3d ago
SOCRadar details DOUBLECUP ClickFix malware delivery service
Initial DisclosureSOCRadar describes DOUBLECUP as a Russian loader-as-a-service that packages ClickFix campaign tooling, provides licenses and a Go-based Windows builder, and supports malware delivery through steganographic PNG images cached in victims' browsers. The service is tied to fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, and SOCRadar says it has operated since early June 2026 while delivering CountLoader to Windows and macOS and a Windows DeviceManager RAT.
Show sources
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT — thehackernews.com — 04.08.2026 12:03