
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
For defenders, the useful question is what this changes about exposure, timing, trust, or control assumptions before the issue turns into someone else's incident review.
What To Know
The real value here is separating the headline from the operational facts: who may be exposed, what preconditions matter, and what readers should verify for themselves.
Why CyberExperts Flagged It
The useful question is not whether this is interesting. It is whether it changes what defenders should prioritize, explain, or stop underestimating.
This matters because ClickFix-style attacks keep evolving faster than user awareness programs do. Hiding payload stages in browser cache artifacts gives attackers another low-friction way to turn a convincing prompt into malware execution.
What Defenders May Be Underestimating
The hidden risk is often not raw technical complexity. It is uncertainty around exposure, ownership, timing, or how much operational drag a delayed response can create once attention shifts from the vulnerability itself to its consequences.
What Teams Should Do Next
- Check asset ownership, remediation timing, and whether this belongs in the current cycle instead of the someday pile.
- Check whether the tactics described map to your current detection coverage, logging visibility, and user or developer exposure points.
- Brief the relevant owners early if the story suggests a shift in attacker tradecraft rather than just another isolated sample.
- Track the original source for updates, scope changes, or newly published mitigation details.
Source Context
CyberExperts is using BleepingComputer as the primary reference for this update.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief