DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A Sophisticated Malware Campaign Exploits Web Vulnerabilities to Deliver Highly Capable Rats

A complex and highly effective malware campaign has been uncovered, leveraging a combination of web application vulnerabilities and clever social engineering tactics to deliver two potent remote access tools (RATs) to unsuspecting victims. Dubbed “DoubleCup,” the operation is notable not only for its technical sophistication but also for its ability to evade detection by traditional security measures.

At the heart of DoubleCup lies a pair of exploits: ClickFix, a vulnerability in web browsers that allows attackers to inject malicious code into websites, and Cached PNGs, a technique used to bypass Content Security Policy (CSP) restrictions. By combining these vulnerabilities, DoubleCup is able to execute a payload on compromised systems, which in turn delivers two highly capable RATs: CountLoader and DeviceManager.

CountLoader is a versatile malware tool that enables attackers to conduct reconnaissance, steal sensitive information, and maintain persistent access to infected systems. Meanwhile, DeviceManager provides the ability to remotely control and manipulate system settings, making it an attractive option for attackers seeking to create complex backdoors or establish long-term access.

What’s particularly concerning about DoubleCup is its ability to evade detection by traditional security measures. By using Cached PNGs to bypass CSP restrictions, attackers can ensure that malicious code remains hidden from view even when security software attempts to scan the compromised system. Furthermore, the use of ClickFix exploits allows attackers to inject malware into legitimate websites, making it difficult for administrators to identify and remediate affected systems.

The implications of DoubleCup are far-reaching, with potential victims including individuals, businesses, and governments worldwide. As a result, it’s essential that organizations take proactive steps to protect themselves against this type of threat. This includes implementing robust web application security measures, such as CSP and browser hardening, as well as conducting regular penetration testing and vulnerability scanning to identify potential entry points.

To mitigate the risks associated with DoubleCup, we recommend that readers take a few key precautions: ensure all software is up-to-date, use reputable anti-virus software and configure it to detect suspicious activity, and implement robust web security measures such as CSP and browser hardening. By staying vigilant and proactive in our approach to cybersecurity, we can better defend ourselves against sophisticated threats like DoubleCup.


Source: The Hacker News — 2026-08-04