Summary Points
- DOUBLECUP uses steganographic PNG images and environmental keying for malware delivery, enabling covert, resilient payload execution across Windows and macOS systems.
- Attackers leverage ClickFix lures on impersonated CRM login sites to initiate multi-stage infections featuring CountLoader and DeviceManager, which exfiltrate data and establish persistence.
- The malware employs advanced evasion techniques such as blockchain-based C2 resolution via EtherHiding and process patching, complicating detection and response efforts.
Threat, Attack Techniques, and Targets
DOUBLECUP is a Russian loader-as-a-service (LaaS) that uses ClickFix to deliver malware. It stage malware in victims’ browser cache by dropping steganographic PNG images. These images hide malicious content that is retrieved and executed in the browser. The process involves decrypting payloads in memory with a custom SHA-256 cipher that uses the victim’s IP address as a key.
The malware delivered includes CountLoader and DeviceManager. CountLoader has versions for Windows and macOS and can establish persistence, check browser extensions, and profile the host. DeviceManager is a Python-based remote access trojan (RAT) that prefers blockchain methods like EtherHiding for command-and-control (C2) resolution. It contacts C2 servers over HTTP or DNS tunneling and is designed to avoid CIS language regions.
The attack relies on fake sites impersonating popular CRM login pages such as Salesforce and NetSuite. Attackers embed iframe elements to deliver the loader and then extract malicious scripts from cache to continue the infection. The operation is controlled via a Telegram bot that tracks and manages infections. Developers provide operators licenses to create campaigns with embedded payloads, managed through a Windows GUI client.
The attack chain includes multiple steps. First, the loader fetches configuration data, then retrieves images, and displays instructions for victims. The malware uses environment checks, like the victim’s IP address, to avoid analysis. Once activated, it connects to the C2 server and executes malicious payloads.
Impact, Security Implications, and Remediation Guidance
DOUBLECUP can lead to severe security issues. It can create persistent backdoors on infected systems, exfiltrate sensitive data, and run additional malicious software. The use of blockchain techniques and environment keying makes detection difficult, increasing the risk of prolonged undetected presence. The malware can also evade process monitoring and analysis.
Due to the sophisticated nature of this threat, organizations should seek remediation guidance from their security vendors or relevant authorities. It is important to review web and endpoint security controls. Organizations should monitor browser cache for suspicious PNG images and block connections to suspicious C2 servers. Regular updates and patches are recommended. If affected, immediately remove suspicious files and consult cybersecurity professionals for cleanup and further analysis.
Discover More Technology Insights
Explore the future of technology with our detailed insights on Artificial Intelligence.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
