Multiple reports describe a Russian loader-as-a-service codenamed DOUBLECUP that uses ClickFix lures to deliver malware through seemingly legitimate PNG files stored in victims’ browser caches. According to the accounts, the infection chain involves a first stage that places a steganographically crafted PNG image into the browser cache. The malware then retrieves the embedded data from the cached image and uses it to execute the next stage.

The sources say this process ultimately delivers CountLoader to both Windows and macOS systems. CountLoader then moves the infection forward. The reports also state that on Windows devices, the campaign includes delivery of a previously undocumented remote access trojan (RAT) named DeviceManager.

While the articles focus on the technical delivery mechanism—staging malicious payloads inside cached images—the overall picture is consistent across outlets: DOUBLECUP operates as a service, leverages ClickFix-style delivery methods, and relies on steganography within PNGs to conceal malicious content until execution. The reports characterize the described malware components and targets but do not provide evidence of public exploitation timelines or affected organizations.