Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: General Windows and macOS users
Incident: Deployment of DOUBLECUP LaaS to deliver CountLoader and DeviceManager RATs via browser-based social engineering.
Impact: Full system compromise and stealthy remote access across multiple operating systems.
Attacker: DOUBLECUP (Russian threat actors)
Analysis: DOUBLECUP employs a multi-stage infection chain that hides payloads within PNG images stored in the browser cache to bypass traditional scanning. It uses environmental keying, specifically the victim’s public IP, to decrypt final payloads in memory. Furthermore, the DeviceManager RAT utilizes blockchain-based C2 resolution, making the infrastructure highly resilient to takedowns.
Recommendations: Implement strict web filtering to block known ClickFix lures and suspicious landing pages.; Deploy EDR solutions capable of detecting memory-only decryption and unusual browser cache executions.; Train users to never copy-paste commands into browser consoles or developer tools based on website prompts.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source