Find notable cyber news and cases, enriched with sources, timelines, and signals.

DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity

Malware Activity
First reported
Last updated
Happening score
H score 19
1 unique sources, 1 articles

Summary

Hide ▲

The DOUBLECUP loader-as-a-service is delivering CountLoader and DeviceManager through ClickFix chains, expanding malware reach across Windows and macOS victims. The service hides payloads in browser-cached PNG images and automates much of the attack infrastructure. The malware set adds persistence, system collection, and command-and-control channels that make the operation harder to disrupt.

Related Happenings

DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS

Threat Actor Meta
H score28 First: 03.08.2026 23:01 Last: 03.08.2026 23:01 Sources 1

How related: DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.

About this happening: DOUBLECUP has emerged as a loader-as-a-service that packages ClickFix campaign infrastructure for paying customers, expanding browser-based malware delivery against ...

DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages

Campaign
H score39 First: 03.08.2026 23:01 Last: 03.08.2026 23:01 Sources 1

How related: SOCRadar says it observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with the malicious code loaded through embedded iframes.

About this happening: The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

Windows cryptocurrency clipper campaign targeting users via USB LNK worms

Campaign
H score32 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...

Venom Stealer MaaS continuous credential theft and exfiltration

Malware Activity
H score29 First: 01.04.2026 16:30 Last: 01.04.2026 16:30 Sources 1

About this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...

Timeline

  1. 03.08.2026 23:01 2 articles · 2h ago

    DOUBLECUP ClickFix service hides malware in browser-cached PNG images

    Initial Disclosure

    SOCRadar reports a Russian loader-as-a-service named DOUBLECUP, operating since early June 2026, that supplies customers with licenses and a Go-based Windows tool for building ClickFix campaigns. The service hosts steganographic PNG images, manages session and signal endpoints, provides encryption keys, and automates payload rebuilding, while customers host the lure sites and add the generated code. Observed campaigns used fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce to deliver CountLoader to Windows and macOS and a DeviceManager RAT to Windows.

    Show sources