DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
Overview
A new Russian malware delivery service known as DOUBLECUP is utilizing a technique called ClickFix to infect users. This method involves embedding malware within PNG images that are stored in victims' browser caches. Once the PNG is loaded, it extracts hidden data and executes two types of malware: CountLoader and a new remote access trojan (RAT) called DeviceManager. This approach allows attackers to bypass traditional security measures and effectively deliver their payloads without raising immediate alarms. Users who fall victim to this scheme could face significant security risks, as the RATs can provide attackers with extensive control over infected devices.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Browser caches, potentially all web browsers capable of rendering PNG images.
- Action Required: Users should clear their browser cache regularly and ensure they have up-to-date security software installed.
- Timeline: Newly disclosed
Original Article Summary
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second
Impact
Browser caches, potentially all web browsers capable of rendering PNG images.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should clear their browser cache regularly and ensure they have up-to-date security software installed. Additionally, organizations should monitor for unusual activity related to browser usage and implement strict web filtering measures.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware, Trojan.