Skip to content

DOUBLECUP

DOUBLECUP is a Russian loader-as-a-service operation active since at least early June 2026 that supports ClickFix-style social-engineering campaigns.

Profile source: Mallory opens in a new tab

DOUBLECUP

Family profile

DOUBLECUP is a Russian loader-as-a-service operation active since at least early June 2026 that supports ClickFix-style social-engineering campaigns. It is designed to help operators deliver malware by staging steganographic payloads inside PNG images that are forced into a victim’s browser cache, then tricking the victim into manually executing a browser-specific command copied to the clipboard via a fake CAPTCHA or verification prompt. Observed lure pages impersonated enterprise and CRM login portals including NetSuite, Odoo, HubSpot, and Salesforce.

The service provides customers with licensed tooling and campaign infrastructure, including a Go-based Windows client for configuring campaigns and generating frontend code for lure sites. DOUBLECUP operators host the steganographic images, manage victim sessions, issue encryption keys, and automatically rebuild payloads. The generated attack flow registers the victim session, identifies the browser, preloads the malicious PNG into cache, and presents execution instructions tailored for browsers such as Chrome, Edge, Firefox, Brave, and Opera.

The execution chain extracts hidden JavaScript, VBScript, or PowerShell from the cached PNG and launches a fileless second-stage dropper. DOUBLECUP uses environmental keying by deriving payload decryption material from the victim’s public IPv4 address, causing the final payload to decrypt correctly only on the intended host and complicating offline sandbox analysis. Reported implementations use a custom SHA-256 CTR-style stream cipher with XOR for in-memory payload decryption.

Observed payloads delivered through DOUBLECUP include updated Windows and macOS variants of CountLoader and a previously undocumented Windows remote access trojan named DeviceManager. CountLoader performs host profiling, searches for cryptocurrency wallet applications and browser extensions, checks for Signal Desktop, establishes persistence through scheduled tasks on Windows or LaunchAgents on macOS, and can download and execute additional payloads such as MSI packages, DLLs, PowerShell modules, and other files. DeviceManager is a modular Python-based RAT that gathers host and user metadata, avoids execution on systems using CIS-language locales, resolves command-and-control infrastructure through EtherHiding using Ethereum or Polygon smart contracts, and communicates over HTTP or DNS to receive commands, exfiltrate data, and download further payloads.

DOUBLECUP reflects the commercialization of ClickFix delivery tradecraft, combining social engineering, steganography, fileless staging, and anti-analysis measures to support post-compromise malware deployment across Windows and macOS environments.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 15, 2026
Last activity
Aug 15, 2026
Feed role
C2
Host form
0 IP / 20 hostnames

Leading locations

  • US8
  • DE5
  • MD1
  • NL1

Leading providers

  • Cloudflare, Inc.8
  • M247 Europe SRL4
  • AVA HOST SRL1
  • DigitalOcean, LLC1
  • The Constant Company, LLC1

Infrastructure traits

  • Hosting 15
  • Anycast 8

Reported operators

Threat actors

1 named in public reporting
Rognar

A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns.

MITRE ATT&CK

DOUBLECUP in ATT&CK

12 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.