A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns.
DOUBLECUP
DOUBLECUP is a Russian loader-as-a-service platform used in ClickFix campaigns since at least early June 2026.
Profile source: Mallory opens in a new tabDOUBLECUP
Family profile
DOUBLECUP is a Russian loader-as-a-service platform used in ClickFix campaigns since at least early June 2026. It is designed to help operators build and run lure-driven malware delivery chains that impersonate business login portals and present fake verification or CAPTCHA prompts to trick victims into manually executing clipboard-delivered commands. Observed lures have impersonated enterprise SaaS and CRM brands including NetSuite, Odoo, HubSpot, and Salesforce.
The service provides licensed tooling and campaign infrastructure, including a Go-based Windows client for configuring campaigns and generating browser-specific delivery code. In observed operations, the lure page registers the victim session, identifies the browser, and forces a malicious PNG image into the browser cache. The copied command then searches the cache for that image, extracts appended or embedded script content using native utilities such as findstr or certutil, and executes a first-stage payload that launches a fileless second-stage dropper.
DOUBLECUP’s delivery chain is notable for combining browser-cache staging with environmental keying. The second stage derives a decryption key from the victim’s public IPv4 address and decrypts the final payload in memory using a custom stream-cipher scheme based on SHA-256 in CTR mode with XOR. This design helps ensure that payload decryption succeeds only on the intended host and can frustrate offline sandboxing and analysis on non-target networks.
Observed payloads delivered through DOUBLECUP include updated Windows and macOS variants of CountLoader and a previously undocumented Windows remote access trojan named DeviceManager. CountLoader performs host profiling, checks for cryptocurrency wallet applications and browser extensions, looks for Signal Desktop, establishes persistence through scheduled tasks on Windows or LaunchAgents on macOS, and can download and execute additional payloads such as MSI packages, DLLs, PowerShell modules, and other files. DeviceManager is a modular Python-based RAT that avoids execution on systems using CIS-language locales, collects host and user metadata, executes commands and scripts, downloads additional payloads, and communicates over HTTP or DNS. It also uses EtherHiding techniques, retrieving command-and-control information from Ethereum or Polygon smart contracts.
DOUBLECUP has been linked in reporting to the threat actor name Rognar and to operational infrastructure that included Telegram-based notifications and campaign management. The platform targets Windows primarily, with observed downstream delivery to both Windows and macOS systems through CountLoader.
Capabilities
- Defense Evasion
- Exfiltration
- Initial Access
- Persistence
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK