SOCRadar’s Threat Research Unit (STRU) identified and analyzed DOUBLECUP, a Russian Loader-as-a-Service (LaaS) for ClickFix campaigns. Operating in a client-server architecture, each client can configure campaigns that host the DOUBLECUP logic on specific URLs.
The DOUBLECUP panel provides multiple utilities to load an operator’s final payload. The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the second stage. This second stage decrypts the final payload in memory via a custom SHA-256 stream cipher in Counter (CTR) mode along with bitwise XOR using the victim’s public IP address as the cryptographic key. Identified payloads loaded by DOUBLECUP include an updated version of CountLoader (with variants for both Windows and macOS) and DeviceManager, a new Remote Access Trojan (RAT) that utilizes EtherHiding to resolve its C2 infrastructure and communicate via HTTP or DNS tunneling.