The threat is a highly advanced malware campaign known as DOUBLECUP, which leverages ClickFix pages to deliver two payloads: an updated variant of CountLoader and a newly uncovered RAT named DeviceManager. The campaign demonstrates evasion at its core, utilizing steganography and environmental keying to bypass defenses. DeviceManager relies on Web3/blockchain-based Command-and-Control (C2) resolution and DNS tunneling for data transport. It resolves its actual C2 server dynamically via the blockchain, a technique known as EtherHiding.
DeviceManager collects extensive system telemetry, including OS version, architecture, machine GUID, hostname, username, antivirus status, domain, and more. DeviceManager supports three command interpreters (CMD, PowerShell, and Python) across two operational modes (in-memory and on-disk). When running in DNS mode, the RAT is hardcoded to execute payloads exclusively in memory. The malware also implements HTTP POST C2 communication and utilizes EtherHiding for resilient C2 infrastructure resolution. DOUBLECUP uses various techniques to evade detection, including reflective code loading, obfuscated files or information, environmental keying, deobfuscation of files or information, and masquerading.[/subscribe_to_unlock_form]
The threat is a highly advanced malware campaign known as DOUBLECUP, which leverages ClickFix pages to deliver two payloads: an updated variant of CountLoader and a newly uncovered RAT named DeviceManager. The campaign demonstrates evasion at its core, utilizing steganography and environmental keying to bypass defenses. DeviceManager relies on Web3/blockchain-based Command-and-Control (C2) resolution and DNS tunneling for data transport. It resolves its actual C2 server dynamically via the blockchain, a technique known as EtherHiding.
DeviceManager collects extensive system telemetry, including OS version, architecture, machine GUID, hostname, username, antivirus status, domain, and more. DeviceManager supports three command interpreters (CMD, PowerShell, and Python) across two operational modes (in-memory and on-disk). When running in DNS mode, the RAT is hardcoded to execute payloads exclusively in memory. The malware also implements HTTP POST C2 communication and utilizes EtherHiding for resilient C2 infrastructure resolution. DOUBLECUP uses various techniques to evade detection, including reflective code loading, obfuscated files or information, environmental keying, deobfuscation of files or information, and masquerading.[emaillocker id="1283"]
The campaign delivers its payloads through phishing pages, compromised websites, and other means. The threat has been observed in multiple regions and has a significant impact on the security landscape. Security teams must prioritize behavioral analytics and telemetry-driven detections to stay ahead of custom loaders and emerging malware families.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1203 | Exploitation for Client Execution | - |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Defence Evasion | T1574.001 | Hijack Execution Flow | DLL |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Execution | E1204 | User Execution |
| Command & Control | B0030 | C2 Communication |
| Command & Control | E1105 | Ingress Tool Transfer |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Discovery | E1082 | System Information Discovery |
| Exfiltration | E1020 | Automated Exfiltration |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Execution | B0023 | Install Additional Program |
| Impact | B0022 | Remote Access |
The following reports contain further technical details:
[/emaillocker]