Russian DOUBLECUP Loader Service Expands Malware Campaigns With ClickFix Technique

Russian DOUBLECUP Loader Service Expands Malware Campaigns With ClickFix Technique

A newly identified Russian loader as a service platform known as DOUBLECUP has been observed using ClickFix lures and steganographic PNG images stored in browser caches to deliver malware, including CountLoader and a previously undocumented remote access trojan named DeviceManager. According to a technical report published by SOCRadar, the malware delivery process begins with a malicious PNG image that is placed into the victim browser cache. Hidden content within the image is then extracted to execute a second stage payload. Researchers explained that the second stage decrypts the final malware directly in memory using a custom SHA 256 stream cipher operating in Counter mode together with bitwise XOR encryption that uses the victim public IP address as the cryptographic key. SOCRadar believes the loader service has been active since early June 2026, providing licensed operators with tools that enable them to create campaigns and distribute malware through ClickFix landing pages.

The investigation began after researchers discovered an exposed directory containing testing files associated with the DOUBLECUP license panel. According to SOCRadar, the service provides operators with unique licenses that include metadata such as client IP addresses, active usage periods, labels, and software versions while allowing multiple campaigns to run under a single license. The Windows client, developed in Go, includes features for updating configurations, managing campaigns, issuing commands, and building payloads through a graphical interface. Operators can configure domains, URLs, archive formats, steganography methods, payload locations, and browser specific commands targeting Chrome, Edge, Firefox, Brave, and Opera. The attack requires threat actors to inject malicious frontend code into ClickFix websites, allowing browsers to retrieve configuration files, prefetch steganographic images, register user sessions, identify the browser type, copy malicious commands to the victim clipboard, and trigger the malware execution sequence. Additional obfuscation and anti analysis features can also be incorporated into payloads by operators. Researchers further identified the use of a Telegram bot named @harrypoterlohBOT to monitor client activity, distribute keys, issue commands, and receive malware callbacks. The bot is reportedly managed by a threat actor using the alias johnnysilverhe, who has also published a suspicious Microsoft Visual Studio Code extension called Agent IDE on the official marketplace.

Campaigns leveraging DOUBLECUP have impersonated well known CRM platforms including NetSuite, Odoo, HubSpot, and Salesforce by creating fraudulent login pages that host embedded iframe elements. Once victims interact with these pages and execute ClickFix commands, malicious JavaScript, VBScript, or PowerShell code hidden inside cached PNG images is extracted to launch the next stage of the infection. The command and control server is then notified before the second stage deploys an encrypted payload and redirects the victim to another webpage. The malware uses environmental keying by deriving the decryption key from the infected machine public IPv4 address, ensuring that the payload can only be successfully unpacked on the intended victim system. One of the primary malware families delivered through this infrastructure is an updated version of CountLoader for both Windows and macOS. The malware establishes persistence through scheduled tasks, audits installed browser extensions for cryptocurrency wallets, profiles infected systems to determine whether the Signal desktop application is installed, and communicates with a command and control server to gather system information, download additional payloads, execute secondary files including DLL, MSI, and HTML Application files, and remove persistence mechanisms that could preserve forensic evidence. Researchers also found unused code capable of modifying browser shortcut files to silently launch both the browser and the malware in the background, although this capability does not currently appear to be active.

The second malware family distributed through DOUBLECUP is DeviceManager, a modular Python based remote access trojan delivered through a Delphi compiled Inno Setup installer containing an encrypted payload and a bundled Python environment. DeviceManager uses EtherHiding to retrieve command and control server details through Ethereum and Polygon smart contracts before communicating over HTTP or DNS tunneling. The malware avoids execution on systems configured with Commonwealth of Independent States language settings by deleting its scheduled tasks, removing its installation directory, and terminating itself if such environments are detected. Once active, DeviceManager collects extensive device information, resolves its command and control infrastructure, downloads additional payloads, executes PowerShell and Python scripts, runs commands through Windows command processor, and reports task results back to operators. SOCRadar stated that DOUBLECUP demonstrates how ClickFix campaigns continue to evolve by combining steganography, environmental keying, blockchain based command and control resolution, and sophisticated evasion techniques to provide threat actors with an efficient malware delivery platform capable of bypassing traditional security defenses.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment