Malware
CountLoader
According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript. They believe it is part of an IAB toolset or used by a affiliate with ties to LockBit, BlackBasta, and Qilin ransomware groups. CountLoader was also recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.
Indicators of Compromise 6
MITRE ATT&CK TTPs 14
T1027 T1059.001 T1071.001 T1071.004 T1105 T1132.001 T1134.002 T1202 T1218.001 T1480 T1496 T1566 T1573.001 T1610
Obfuscated Files or Information
Defense Evasion
PowerShell
Execution
Web Protocols
Command And Control
DNS
Command And Control
Ingress Tool Transfer
Command And Control
Standard Encoding
Command And Control
Create Process with Token
Defense Evasion
Indirect Command Execution
Defense Evasion
Compiled HTML File
Defense Evasion
Execution Guardrails
Defense Evasion
Resource Hijacking
Impact
Phishing
Initial Access
Symmetric Cryptography
Command And Control
Deploy Container
Defense Evasion
Source Articles
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
The DOUBLECUP loader-as-a-service (LaaS) is being used by threat actors to deliver malware such as CountLoader and a previously undocumented Python-based remote access trojan (RAT) called DeviceManager. The attack begins with social engineering lures via fake CRM login pages using ClickFix, which trigger the download of steganographically encoded PNG images into the browser cache. These images contain hidden payloads that, when extracted, execute malicious code to deploy the final malware. CountLoader uses environmental keying based on the victim's public IP address for decryption and establishes persistence by modifying browser shortcuts, while DeviceManager leverages blockchain-based C2 resolution via Ethereum/Polygon smart contracts using EtherHiding.
hacker-news ·4w ago
New DOUBLECUP ClickFix service hides malware in browser cache images
A Russian loader-as-a-service named DOUBLECUP has been active since June 2026, enabling threat actors to conduct ClickFix attacks by hiding malicious payloads in steganographic PNG images cached in victims' browsers. The service provides infrastructure for hosting malicious images, managing sessions, and delivering payloads, which include an updated CountLoader malware and a new Python-based RAT called DeviceManager. Victims are lured to malicious sites impersonating legitimate services like NetSuite and Salesforce, where fake CAPTCHA prompts trick them into executing commands that extract and run malware from the browser cache. DeviceManager uses blockchain smart contracts (EtherHiding) to dynamically retrieve C2 addresses, enhancing resilience against takedown efforts.
bleeping-computer ·4w ago