DOUBLECUP Malware Service Hides Payloads in Browser Cache Images via Fake CAPTCHAs
A Russian Loader-as-a-Service operation called DOUBLECUP has been identified using fake CAPTCHA prompts to trick users into running malicious clipboard commands on Windows and macOS systems. The service operates by embedding encrypted malware payloads inside PNG images stored in the browser cache, with decryption keys derived from the victim's public IP address. Operators deploy lookalike websites impersonating business platforms such as HubSpot, Salesforce, NetSuite, and Odoo to lure targets. Once executed, the fileless payload delivers either CountLoader, which harvests crypto wallets and browser data, or DeviceManager RAT, which locates its command-and-control server via Ethereum and Polygon smart contracts. Security researchers flagged the threat in August 2026, rating its severity as high and advising defenders to monitor abnormal browser-to-PowerShell process chains and block suspicious clipboard activity.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in