logo

Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs

ID: 20d6b74d-2c26-5914-b3ff-a3695014d13a

STIX ID: report--20d6b74d-2c26-5914-b3ff-a3695014d13a

Feed Name: SOCRadar Blog

Threat Score
80/100

Date Published: 2026-08-03

Date Updated: 2026-08-19

Author: ameer

...
...

**Executive summary:** This report details DOUBLECUP, a Russian Loader-as-a-Service used in ClickFix lure campaigns that delivers steganographic, browser-targeted multi-stage payloads; it documents the loader's architecture and operational chain and analyzes two final payloads—CountLoader (Windows/macOS RAT/loader) and DeviceManager (Python RAT using blockchain-based C2 and DNS tunneling)—including persistence, evasion, C2 methods, TTPs, and IoCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.