DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware Activity
Summary
Hide ▲
Show ▼
The DOUBLECUP loader-as-a-service is delivering CountLoader and DeviceManager through ClickFix chains, expanding malware reach across Windows and macOS victims. The service hides payloads in browser-cached PNG images and automates much of the attack infrastructure. The malware set adds persistence, system collection, and command-and-control channels that make the operation harder to disrupt.
Related Happenings
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor Meta
H score28
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
How related:
DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.
About this happening:
DOUBLECUP has emerged as a loader-as-a-service that packages ClickFix campaign infrastructure for paying customers, expanding browser-based malware delivery against ...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor MetaHow related: DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.
About this happening: DOUBLECUP has emerged as a loader-as-a-service that packages ClickFix campaign infrastructure for paying customers, expanding browser-based malware delivery against ...
DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages
Campaign
H score39
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
How related:
SOCRadar says it observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with the malicious code loaded through embedded iframes.
About this happening:
The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...
DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages
CampaignHow related: SOCRadar says it observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with the malicious code loaded through embedded iframes.
About this happening: The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
Campaign
H score32
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
CampaignAbout this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware Activity
H score29
First: 01.04.2026 16:30
Last: 01.04.2026 16:30
Sources 1
About this happening:
The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware ActivityAbout this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Timeline
-
03.08.2026 23:01 2 articles · 2h ago
DOUBLECUP ClickFix service hides malware in browser-cached PNG images
Initial DisclosureSOCRadar reports a Russian loader-as-a-service named DOUBLECUP, operating since early June 2026, that supplies customers with licenses and a Go-based Windows tool for building ClickFix campaigns. The service hosts steganographic PNG images, manages session and signal endpoints, provides encryption keys, and automates payload rebuilding, while customers host the lure sites and add the generated code. Observed campaigns used fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce to deliver CountLoader to Windows and macOS and a DeviceManager RAT to Windows.
Show sources
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01