DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware Activity
Summary
Hide ▲
Show ▼
DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoader and a previously undocumented DeviceManager RAT. SOCRadar says the service provides licenses, a client agent, session and signal endpoints, encryption keys, and campaign-building tooling, while operators host lure sites and add the generated code. Observed campaigns used fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce. The payload chain adds persistence, system collection, and C2 channels, including EtherHiding, HTTP, and DNS tunneling.
Related Happenings
ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
H score22
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
ClickFix AmnesiaStealer distribution campaign targeting mac users
CampaignAbout this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
Latest development: 16.08.2026 18:07
Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignAbout this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix Go-based macOS infostealer and crypto drainer
Malware Activity
H score29
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
ClickFix Go-based macOS infostealer and crypto drainer
Malware ActivityAbout this happening: A Go-based malware delivered through ClickFix is targeting macOS users to steal cryptocurrency assets, browser-stored passwords, Apple iCloud Keychain data...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor Meta
H score28
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
How related:
DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.
About this happening:
DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor MetaHow related: DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.
About this happening: DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
Timeline
-
03.08.2026 23:01 3 articles · 13d ago
DOUBLECUP ClickFix service hides malware in browser-cached PNG images
Initial DisclosureSOCRadar reports a Russian loader-as-a-service named DOUBLECUP, operating since early June 2026, that supplies customers with licenses and a Go-based Windows tool for building ClickFix campaigns. The service hosts steganographic PNG images, manages session and signal endpoints, provides encryption keys, and automates payload rebuilding, while customers host the lure sites and add the generated code. Observed campaigns used fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce to deliver CountLoader to Windows and macOS and a DeviceManager RAT to Windows.
Show sources
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT — thehackernews.com — 04.08.2026 12:03