DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages
Campaign
Summary
Hide ▲
Show ▼
The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into running malicious commands, expanding malware-delivery risk across SaaS users. The lure pages rely on embedded iframes and browser-cache abuse to move victims into the payload chain. The operation is part of a broader DOUBLECUP service model that lets customers build and launch these attack pages.
Related Happenings
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor Meta
H score28
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
How related:
DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.
About this happening:
DOUBLECUP has emerged as a loader-as-a-service that packages ClickFix campaign infrastructure for paying customers, expanding browser-based malware delivery against ...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor MetaHow related: DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.
About this happening: DOUBLECUP has emerged as a loader-as-a-service that packages ClickFix campaign infrastructure for paying customers, expanding browser-based malware delivery against ...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware Activity
H score19
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
How related:
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
About this happening:
The DOUBLECUP loader-as-a-service is delivering CountLoader and DeviceManager through ClickFix chains, expanding malware reach across Windows and macOS vic...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware ActivityHow related: A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
About this happening: The DOUBLECUP loader-as-a-service is delivering CountLoader and DeviceManager through ClickFix chains, expanding malware reach across Windows and macOS vic...
DriveSurge large-scale website-hijack malware distribution campaign
Campaign
H score41
First: 02.06.2026 01:14
Last: 02.06.2026 01:14
Sources 1
About this happening:
The DriveSurge campaign is redirecting visitors from thousands of compromised websites to malware-delivery infrastructure, creating a broad infection path through Cl...
DriveSurge large-scale website-hijack malware distribution campaign
CampaignAbout this happening: The DriveSurge campaign is redirecting visitors from thousands of compromised websites to malware-delivery infrastructure, creating a broad infection path through Cl...
UNC1069 GhostCall cryptocurrency social-engineering campaign
Campaign
H score37
First: 11.02.2026 08:50
Last: 11.02.2026 08:50
Sources 1
About this happening:
UNC1069 is actively targeting the cryptocurrency sector with a social-engineering campaign designed to steal credentials and data for financial theft. The operatio...
UNC1069 GhostCall cryptocurrency social-engineering campaign
CampaignAbout this happening: UNC1069 is actively targeting the cryptocurrency sector with a social-engineering campaign designed to steal credentials and data for financial theft. The operatio...
Timeline
-
03.08.2026 23:01 2 articles · 2h ago
DOUBLECUP ClickFix campaigns impersonate NetSuite, Odoo, HubSpot, and Salesforce login pages
Initial DisclosureSOCRadar observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with malicious code loaded through embedded iframes. When a victim opens one of these pages, the campaign registers the session, identifies the victim's public IP address, forces a malicious PNG image into the browser cache, and then relies on copied commands to recover the hidden payload. The loader-as-a-service has operated since early June 2026 and its campaign chain ultimately delivers CountLoader to Windows and macOS devices and a DeviceManager RAT to Windows systems.
Show sources
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01