threat-intel
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
High
Summary
DOUBLECUP, a new Russian LaaS service, is using ClickFix lures to deliver malware, specifically CountLoader (Windows and macOS) and DeviceManager (Windows and macOS). DeviceManager utilizes blockchain-based C2 resolution (EtherHiding) for resilience and avoids targeting CIS regions. DOUBLECUP provides a streamlined payload delivery pipeline, leveraging steganography and environmental keying to evade detection, and is operated by a threat actor known as "johnnysilverhe" who has also released a suspicious VS Code extension.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
