New DOUBLECUP ClickFix Service Hides Malware in Browser Cache Images

A new Russian loader-as-a-service called DOUBLECUP uses ClickFix attacks to hide malware within PNG images cached by victims' browsers, delivering CountLoader malware for Windows and macOS and a new DeviceManager RAT for Windows. The attack involves fake CAPTCHA prompts on spoofed login pages that trick users into running commands which extract and execute hidden payloads from browser cache images, enabling stealthy system compromise and persistence. DeviceManager uses blockchain smart contracts to dynamically retrieve command-and-control server addresses, enhancing its resilience against takedown efforts.

https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top