Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
ID: 20d6b74d-2c26-5914-b3ff-a3695014d13a
STIX ID: report--20d6b74d-2c26-5914-b3ff-a3695014d13a
Feed Name: SOCRadar Blog
Threat Score
**Executive summary:** This report details DOUBLECUP, a Russian Loader-as-a-Service used in ClickFix lure campaigns that delivers steganographic, browser-targeted multi-stage payloads; it documents the loader's architecture and operational chain and analyzes two final payloads—CountLoader (Windows/macOS RAT/loader) and DeviceManager (Python RAT using blockchain-based C2 and DNS tunneling)—including persistence, evasion, C2 methods, TTPs, and IoCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
