Last seven days
- First activity
- Aug 15, 2026
- Last activity
- Aug 15, 2026
- Feed role
- C2
- Host form
- 0 IP / 20 hostnames
DOUBLECUP is a Russian loader-as-a-service operation active since at least early June 2026 that supports ClickFix-style social-engineering campaigns.
Profile source: Mallory opens in a new tabDOUBLECUP
DOUBLECUP is a Russian loader-as-a-service operation active since at least early June 2026 that supports ClickFix-style social-engineering campaigns. It is designed to help operators deliver malware by staging steganographic payloads inside PNG images that are forced into a victim’s browser cache, then tricking the victim into manually executing a browser-specific command copied to the clipboard via a fake CAPTCHA or verification prompt. Observed lure pages impersonated enterprise and CRM login portals including NetSuite, Odoo, HubSpot, and Salesforce.
The service provides customers with licensed tooling and campaign infrastructure, including a Go-based Windows client for configuring campaigns and generating frontend code for lure sites. DOUBLECUP operators host the steganographic images, manage victim sessions, issue encryption keys, and automatically rebuild payloads. The generated attack flow registers the victim session, identifies the browser, preloads the malicious PNG into cache, and presents execution instructions tailored for browsers such as Chrome, Edge, Firefox, Brave, and Opera.
The execution chain extracts hidden JavaScript, VBScript, or PowerShell from the cached PNG and launches a fileless second-stage dropper. DOUBLECUP uses environmental keying by deriving payload decryption material from the victim’s public IPv4 address, causing the final payload to decrypt correctly only on the intended host and complicating offline sandbox analysis. Reported implementations use a custom SHA-256 CTR-style stream cipher with XOR for in-memory payload decryption.
Observed payloads delivered through DOUBLECUP include updated Windows and macOS variants of CountLoader and a previously undocumented Windows remote access trojan named DeviceManager. CountLoader performs host profiling, searches for cryptocurrency wallet applications and browser extensions, checks for Signal Desktop, establishes persistence through scheduled tasks on Windows or LaunchAgents on macOS, and can download and execute additional payloads such as MSI packages, DLLs, PowerShell modules, and other files. DeviceManager is a modular Python-based RAT that gathers host and user metadata, avoids execution on systems using CIS-language locales, resolves command-and-control infrastructure through EtherHiding using Ethereum or Polygon smart contracts, and communicates over HTTP or DNS to receive commands, exfiltrate data, and download further payloads.
DOUBLECUP reflects the commercialization of ClickFix delivery tradecraft, combining social engineering, steganography, fileless staging, and anti-analysis measures to support post-compromise malware deployment across Windows and macOS environments.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.