DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor Meta
Summary
Hide ▲
Show ▼
DOUBLECUP has emerged as a loader-as-a-service that packages ClickFix campaign infrastructure for paying customers, expanding browser-based malware delivery against Windows and macOS victims. The service supplies licenses, a Go-based Windows tool, and backend components that reduce the work required to run malicious campaigns. Its operating model lowers the barrier for other operators to deliver loaders such as CountLoader and DeviceManager.
Related Happenings
DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages
Campaign
H score39
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
How related:
SOCRadar says it observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with the malicious code loaded through embedded iframes.
About this happening:
The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...
DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages
CampaignHow related: SOCRadar says it observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with the malicious code loaded through embedded iframes.
About this happening: The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware Activity
H score19
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
How related:
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
About this happening:
The DOUBLECUP loader-as-a-service is delivering CountLoader and DeviceManager through ClickFix chains, expanding malware reach across Windows and macOS vic...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware ActivityHow related: A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
About this happening: The DOUBLECUP loader-as-a-service is delivering CountLoader and DeviceManager through ClickFix chains, expanding malware reach across Windows and macOS vic...
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
UAT-9244 TernDoor, PeerTime, and BruteEntry malware activity
Malware Activity
H score22
First: 06.03.2026 01:19
Last: 06.03.2026 01:19
Sources 1
About this happening:
A China-linked malware cluster has been using TernDoor, PeerTime, and BruteEntry to compromise telecommunication providers in South America and turn infected s...
UAT-9244 TernDoor, PeerTime, and BruteEntry malware activity
Malware ActivityAbout this happening: A China-linked malware cluster has been using TernDoor, PeerTime, and BruteEntry to compromise telecommunication providers in South America and turn infected s...
LummaStealer infection surge via CastleLoader
Malware Activity
H score30
First: 11.02.2026 19:02
Last: 11.02.2026 19:02
Sources 1
About this happening:
The LummaStealer infostealer operation now includes a widespread ClickFix campaign observed in February 2026 that abuses Windows Terminal (wt.exe) instead of the R...
LummaStealer infection surge via CastleLoader
Malware ActivityAbout this happening: The LummaStealer infostealer operation now includes a widespread ClickFix campaign observed in February 2026 that abuses Windows Terminal (wt.exe) instead of the R...
Latest development: 06.03.2026 08:44
Microsoft disclosed a widespread ClickFix social-engineering campaign that uses Windows Terminal (wt.exe) instead of the Windows Run dialog to trick users into launching malicious commands, then chains through Terminal, PowerShell, cmd.exe, and MSBuild.exe to download payloads, set persistence via scheduled tasks, configure Microsoft Defender exclusions, and inject Lumma Stealer into chrome.exe and msedge.exe with QueueUserAPC().
Timeline
-
03.08.2026 23:01 2 articles · 2h ago
SOCRadar details DOUBLECUP ClickFix malware delivery service
Initial DisclosureSOCRadar describes DOUBLECUP as a Russian loader-as-a-service that packages ClickFix campaign tooling, provides licenses and a Go-based Windows builder, and supports malware delivery through steganographic PNG images cached in victims' browsers. The service is tied to fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, and SOCRadar says it has operated since early June 2026 while delivering CountLoader to Windows and macOS and a Windows DeviceManager RAT.
Show sources
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01
- New DOUBLECUP ClickFix service hides malware in browser cache images — www.bleepingcomputer.com — 03.08.2026 23:01