Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DOUBLECUP’s Innovative Malware Delivery via Steganography

DOUBLECUP’s Innovative Malware Delivery via Steganography

Posted on August 4, 2026 By CWS

A newly identified malware delivery service, known as DOUBLECUP, has emerged from Russia, employing an innovative technique using ClickFix lures and steganographic PNGs to distribute malicious software. This service targets unsuspecting users by embedding malware within PNG images stored in browser caches, ultimately deploying the CountLoader and a previously undocumented remote access trojan (RAT) named DeviceManager.

Steganographic Techniques and Payload Delivery

According to SOCRadar’s technical analysis, the initial phase involves placing a steganographic PNG file in the browser’s cache, which contains concealed data that activates the next stage of the attack. This subsequent stage decrypts the malware payload in memory, utilizing a custom SHA-256 stream cipher in Counter mode and applying bitwise XOR with the victim’s public IP as the cryptographic key.

The service facilitates the delivery of payloads like CountLoader and DeviceManager across both Windows and macOS. DeviceManager, in particular, employs a technique called EtherHiding to manage its command-and-control (C2) infrastructure, facilitating communication via HTTP or DNS tunneling.

Operational Details and Client Support

DOUBLECUP has been in operation since June 2026, providing clients with licenses and a specialized client agent to support the creation and execution of campaigns. Each license is unique, containing metadata such as the client’s IP address, active days, label, and version. This allows operators to manage multiple campaigns per license.

The Windows-based GUI client allows operators to update configurations and issue commands through a Broadcast Pane, while a Payload Builder Pane helps set up commands triggered by ClickFix decoys. These decoys configure domains, steganography methods, and payload URLs, creating a configuration endpoint for retrieving DOUBLECUP’s setup data.

Advanced Obfuscation and Threat Management

To execute the attack, operators must inject specific frontend code onto their ClickFix sites. This involves fetching configuration data, prefetching the image, and evaluating browser User-Agent strings to select suitable payloads. The process culminates with a polling mechanism to execute the final redirect, potentially incorporating additional obfuscation tactics at the operator’s discretion.

A Telegram bot is used for tracking client interactions, delivering commands, and managing payload callbacks via a designated URL. The bot is allegedly managed by a threat actor known as “johnnysilverhe,” who also published a suspicious Visual Studio Code extension.

Implications and Future Outlook

DOUBLECUP campaigns have utilized fake CRM login sites to distribute loaders, which execute ClickFix commands to extract malicious scripts from the browser cache. Upon infection, the C2 server is alerted, and further payload deployment is triggered, employing environmental keying to ensure activation solely on targeted machines.

The sophisticated use of steganography and environmental keying by DOUBLECUP demonstrates a significant evolution in malware delivery methods, offering threat actors a reliable and evasive payload distribution channel. As cybersecurity defenses advance, the need for vigilance and innovative countermeasures continues to grow.

The Hacker News Tags:browser cache, ClickFix, CountLoader, Cybersecurity, DeviceManager, DOUBLECUP, Malware, payload delivery, remote access trojan, Steganography

Post navigation

Previous Post: Old BMC Flaw Threatens Thousands of Data Centers
Next Post: Gemini Attack Method Exposes Secrets, Risks PR Manipulation

Related Posts

Qilin Ransomware Exploits PAN-OS Vulnerability for Access Qilin Ransomware Exploits PAN-OS Vulnerability for Access The Hacker News
How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year? How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year? The Hacker News
Wazuh for Regulatory Compliance Wazuh for Regulatory Compliance The Hacker News
FBI and Europol Dismantle Cybercrime Forum LeakBase FBI and Europol Dismantle Cybercrime Forum LeakBase The Hacker News
New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims The Hacker News
China-Linked UAT-8302 Targets Global Governments with APT Malware China-Linked UAT-8302 Targets Global Governments with APT Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Exploiting AI Agents: New Threat to Software Supply Chains
  • Gemini Attack Method Exposes Secrets, Risks PR Manipulation
  • DOUBLECUP’s Innovative Malware Delivery via Steganography
  • Old BMC Flaw Threatens Thousands of Data Centers
  • North Korean Hackers Conceal Malware in Crypto Transfers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Exploiting AI Agents: New Threat to Software Supply Chains
  • Gemini Attack Method Exposes Secrets, Risks PR Manipulation
  • DOUBLECUP’s Innovative Malware Delivery via Steganography
  • Old BMC Flaw Threatens Thousands of Data Centers
  • North Korean Hackers Conceal Malware in Crypto Transfers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark