Critical

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

The Hacker News
Actively Exploited

Overview

A new Russian malware delivery service known as DOUBLECUP is utilizing a technique called ClickFix to infect users. This method involves embedding malware within PNG images that are stored in victims' browser caches. Once the PNG is loaded, it extracts hidden data and executes two types of malware: CountLoader and a new remote access trojan (RAT) called DeviceManager. This approach allows attackers to bypass traditional security measures and effectively deliver their payloads without raising immediate alarms. Users who fall victim to this scheme could face significant security risks, as the RATs can provide attackers with extensive control over infected devices.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Browser caches, potentially all web browsers capable of rendering PNG images.
  • Action Required: Users should clear their browser cache regularly and ensure they have up-to-date security software installed.
  • Timeline: Newly disclosed

Original Article Summary

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second

Impact

Browser caches, potentially all web browsers capable of rendering PNG images.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should clear their browser cache regularly and ensure they have up-to-date security software installed. Additionally, organizations should monitor for unusual activity related to browser usage and implement strict web filtering measures.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Malware, Trojan.

Related Coverage

Dem senators criticize Trump administration decisionmaking on AI security risks

CyberScoop

Five Democratic senators have expressed their concerns over the Trump administration's approach to managing artificial intelligence (AI) security risks. They argue that the administration has been inconsistent, sometimes too passive and at other times overreaching, which they believe has created an environment where China could gain an advantage in AI development. The senators are urging for a more balanced and proactive strategy to address the growing security challenges posed by AI technologies. This situation is critical as AI continues to evolve rapidly, impacting various sectors, including defense and cybersecurity. The senators' critique highlights the need for a clear and effective policy to mitigate potential risks associated with AI advancements.

Aug 4, 2026

Massive ChainDrop npm supply-chain attack infects hundreds of packages

BleepingComputer

A new self-propagating malware called 'ChainDrop' has infected over 1,300 packages in the Node Package Manager (npm) registry, which collectively see around 2 billion downloads each month. This attack allows the malware to spread rapidly across various software projects that rely on npm packages. Developers and companies using these compromised packages are at risk of introducing vulnerabilities into their applications. The incident raises significant concerns about supply chain security, as it demonstrates how a single attack can impact a vast number of users and systems. Those affected should take immediate steps to identify and remove the compromised packages from their projects to mitigate potential damage.

Aug 4, 2026

Prolific ransomware group behind SonicWall zero-day attacks

CyberScoop

The INC ransomware group has been linked to recent attacks exploiting zero-day vulnerabilities in SonicWall products. While they weren't the first to take advantage of these flaws, their aggressive tactics in combining both vulnerabilities have made them particularly effective at stealing and encrypting sensitive data for ransom. This situation poses a significant risk for organizations using affected SonicWall devices, as it can lead to severe data breaches and financial losses. Users and companies relying on SonicWall's security products need to be vigilant and implement necessary precautions to protect their systems. The ongoing threat from INC highlights the importance of timely updates and monitoring for unusual activity in network environments.

Aug 4, 2026

WhatsApp Scam Hijacks Accounts via Linked Devices Feature

Infosecurity Magazine

A recent WhatsApp scam has exploited the app's Linked Devices feature to take control of user accounts without needing to steal passwords. This method allows attackers to gain access to someone's WhatsApp by tricking them into providing a verification code. Victims are often misled into thinking they are verifying their own devices, making it easier for scammers to hijack accounts. This incident raises significant concerns about the security of user accounts on popular messaging platforms, especially as more people rely on these apps for personal and professional communication. Users should be cautious and verify any unexpected requests for verification codes to protect their accounts.

Aug 4, 2026

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

SecurityWeek

Researchers have found that built-in email chatbots could be weaponized by attackers to impersonate trusted employees, potentially leading to account hijacking and financial fraud. These AI assistants, often designed to make email communication more efficient, can be exploited to bypass security measures and compromise executive accounts. This poses a significant risk to organizations, as attackers could manipulate these tools to send deceptive messages that appear legitimate to recipients. The implications are serious, as companies may face not only financial losses but also damage to their reputations. Users and organizations need to be aware of these vulnerabilities and take steps to secure their email systems against such tactics.

Aug 4, 2026

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

The Hacker News

A credential-stealing worm linked to the npm package 'keyv' has spread to hundreds of packages since it was first identified on August 4, 2026. This malware has affected at least 868 packages according to Aikido, with SafeDep confirming 353 poisoned versions across 79 package names in the npm registry. The worm is designed to steal user credentials and has also incorporated hooks for the Claude code and Visual Studio Code environments. This incident raises serious concerns for developers and organizations using these packages, as compromised libraries can lead to significant security breaches and data loss. Users are urged to audit their dependencies and ensure they are using safe versions of affected packages.

Aug 4, 2026