Tag: DeviceManager RAT

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
News

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

ClickFix lures have been used by a new Russian loader-as-a-service (LaaS) nicknamed DOUBLECUP to stage malware-laden PNG images in victims' browser cache before delivering CountLoader and DeviceManager, an unreported remote access trojan. According to a technical assessment from SOCRadar, the first stage loads a steganographic PNG image into the browser's cache, extracts its concealed content, and then starts the second stage. Using the victim's public IP address as the cryptographic key, this second step uses bitwise XOR and a bespoke SHA-256 stream cipher in Counter (CTR) mode to decrypt the final payload in memory. The loader service delivers payloads such as DeviceManager, which uses EtherHiding to resolve its command-and-control (C2) infrastructure and communicate with the serv...