Malware

CountLoader

According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript. They believe it is part of an IAB toolset or used by a affiliate with ties to LockBit, BlackBasta, and Qilin ransomware groups. CountLoader was also recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.

Indicators of Compromise 6

MITRE ATT&CK TTPs 14

Source Articles

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
The DOUBLECUP loader-as-a-service (LaaS) is being used by threat actors to deliver malware such as CountLoader and a previously undocumented Python-based remote access trojan (RAT) called DeviceManager. The attack begins with social engineering lures via fake CRM login pages using ClickFix, which trigger the download of steganographically encoded PNG images into the browser cache. These images contain hidden payloads that, when extracted, execute malicious code to deploy the final malware. CountLoader uses environmental keying based on the victim's public IP address for decryption and establishes persistence by modifying browser shortcuts, while DeviceManager leverages blockchain-based C2 resolution via Ethereum/Polygon smart contracts using EtherHiding.
hacker-news ·4w ago
New DOUBLECUP ClickFix service hides malware in browser cache images
A Russian loader-as-a-service named DOUBLECUP has been active since June 2026, enabling threat actors to conduct ClickFix attacks by hiding malicious payloads in steganographic PNG images cached in victims' browsers. The service provides infrastructure for hosting malicious images, managing sessions, and delivering payloads, which include an updated CountLoader malware and a new Python-based RAT called DeviceManager. Victims are lured to malicious sites impersonating legitimate services like NetSuite and Salesforce, where fake CAPTCHA prompts trick them into executing commands that extract and run malware from the browser cache. DeviceManager uses blockchain smart contracts (EtherHiding) to dynamically retrieve C2 addresses, enhancing resilience against takedown efforts.
bleeping-computer ·4w ago