New DOUBLECUP ClickFix service hides malware in browser cache images

By George Bailey   Published: 08/03/26   Updated: 08/03/26   2 min read
New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.

For defenders, the useful question is what this changes about exposure, timing, trust, or control assumptions before the issue turns into someone else's incident review.

What To Know

The real value here is separating the headline from the operational facts: who may be exposed, what preconditions matter, and what readers should verify for themselves.

Why CyberExperts Flagged It

The useful question is not whether this is interesting. It is whether it changes what defenders should prioritize, explain, or stop underestimating.

This matters because ClickFix-style attacks keep evolving faster than user awareness programs do. Hiding payload stages in browser cache artifacts gives attackers another low-friction way to turn a convincing prompt into malware execution.

What Defenders May Be Underestimating

The hidden risk is often not raw technical complexity. It is uncertainty around exposure, ownership, timing, or how much operational drag a delayed response can create once attention shifts from the vulnerability itself to its consequences.

What Teams Should Do Next

Source Context

CyberExperts is using BleepingComputer as the primary reference for this update.

Related In The Daily Brief

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading