DOUBLECUP ClickFix Loader Delivers CountLoader and DeviceManager RATs
Executive Summary A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns. The service enables operators to configure malicious lure pages that instruct victims to copy and execute commands from fake verification prompts. DOUBLECUP retrieves hidden code from a steganographic PNG cached by the victim’s browser…
Read More