Login
← All news

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

The Hacker News Security

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second…

Read the full story on The Hacker News https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html
Attacks like this land on ordinary sites far more often than on chosen targets. If you would rather your site never became the story, CrockyHost hosting ships with daily backups, automatic updates and a firewall we manage.