What Happened
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second
Why It Matters
The report describes DOUBLECUP, a Russian loader-as-a-service that uses ClickFix lures and steganographic PNGs cached in browsers to deliver CountLoader and a previously undocumented RAT called DeviceManager.[1][2] It also says DeviceManager uses EtherHiding and HTTP or DNS tunneling for C2, while CountLoader can establish persistence and gather host data.[1][2] RealGround analysis: this is primarily a malware delivery and execution campaign, so the main security implication is monitoring for browser-cache-based payload extraction, suspicious script execution, and DNS tunneling indicators rather than an AI-specific threat.
RealGround Analysis
This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html
