Alanna
River

DOUBLECUP ClickFix Malware: Browser Cache, SaaS Lures, and Enterprise Endpoint Risk

Alanna River

Aug 4, 2026

3 min read

Spyware Computer Hacker Virus Malware Concept

The "What Happened"

  • BleepingComputer reported on DOUBLECUP, a Russian loader-as-a-service that uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers.
  • SOCRadar said DOUBLECUP has operated since early June 2026 and provides customers with licenses and a Go-based Windows tool for creating malicious campaigns.
  • Observed campaigns used fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with malicious code loaded through embedded iframes.
  • The attack preloads a steganographic PNG into the browser cache and tricks the victim into running a copied command that searches the cache and extracts the hidden payload.
  • DOUBLECUP has delivered CountLoader for Windows and macOS and a previously undocumented Python-based Windows remote access trojan called DeviceManager.
  • CountLoader can collect system details, check for cryptocurrency wallets and browser extensions, identify Signal Desktop installations, establish persistence, and download additional files.
  • DeviceManager uses EtherHiding to retrieve command-and-control infrastructure from Ethereum or Polygon smart contracts and uses DNS records to exchange system data, commands, payloads, and command output.

A new Russian loader-as-a-service, DOUBLECUP, is combining ClickFix social engineering with an unusual payload-staging technique. The campaign hides malicious code inside PNG images stored in the browser cache, then uses fake SaaS login pages and CAPTCHA prompts to trick users into executing commands that extract and run the payload.

Inside the DOUBLECUP Attack Chain

DOUBLECUP provides its customers with a Go-based campaign builder that generates the components needed for a ClickFix attack, including steganographic image references, browser-specific commands, session endpoints, and payload locations. Researchers observed the service distributing both CountLoader and a previously undocumented DeviceManager remote access trojan through this workflow.

When a victim lands on a fake login page, the attack first registers the session, identifies the browser, and forces it to cache a malicious PNG image. It then copies a command to the victim’s clipboard and instructs them to paste and run it under the guise of completing a CAPTCHA or verification step.

If the victim follows the ClickFix instructions, built-in Windows utilities such as findstr or certutil locate the cached image and recover the hidden first-stage payload. The malware then launches a fileless dropper, which decrypts and executes the final payload without relying on a conventional installer. Depending on the campaign, the final malware can be CountLoader or DeviceManager, enabling attackers to establish persistence, collect system information, and deploy additional payloads.

The Hexnode Solution

Organizations can reduce the risk of ClickFix-based malware campaigns by combining endpoint detection, device hardening, and device compliance enforcement.

  • Hexnode XDR can help detect suspicious process trees—such as browser processes spawning administrative utilities (certutil, findstr) or unexpected command-line arguments—and enable one-click process termination and device isolation.
  • Hexnode UEM can help enforce browser security baselines, Web Content Filtering policies, application controls, and script execution restrictions. It can also enforce Windows and macOS security configurations and OS update compliance to reduce the attack surface and keep managed devices aligned with security policies.
  • Hexnode Access and IdP-driven Conditional Access integrations with identity providers such as Microsoft Entra ID and Okta can further limit the impact of compromised endpoints by restricting enterprise SaaS application access to compliant and managed devices, helping ensure non-compliant or unmanaged endpoints cannot access business-critical resources even if attackers obtain valid credentials or sessions.
Device Lifecycle Management: Complete End-to-End Framework
Feature Resource

Device Lifecycle Management: Complete End-to-End Framework

Visualize the complete device lifecycle and automate management with Hexnode effortlessly.

Get the infographic

Conclusion

DOUBLECUP demonstrates how ClickFix campaigns continue to evolve with more automated delivery methods, steganographic payloads, and convincing impersonation of trusted business applications. As attackers blend social engineering with fileless execution and evasive infrastructure, traditional signature-based defenses alone become less effective.

To reduce exposure, organizations should:

  • Strengthen UEM configuration baselines by hardening browser settings, restricting script and command execution, and keeping operating systems and applications up to date.
  • Use XDR behavioral monitoring to detect suspicious browser-spawned processes, abnormal command-line activity, persistence mechanisms, and other indicators of ClickFix-related malware.
  • Enforce IdP-driven Conditional Access to ensure only compliant, managed devices can access enterprise SaaS applications, limiting the impact of compromised endpoints and stolen sessions.
Share

Alanna River

I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.