Threat Advisory

CountLoader C2 Commands Execute Arbitrary Code and Conduct Lateral Movement

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The threat is a highly advanced malware campaign known as DOUBLECUP, which leverages ClickFix pages to deliver two payloads: an updated variant of CountLoader and a newly uncovered RAT named DeviceManager. The campaign demonstrates evasion at its core, utilizing steganography and environmental keying to bypass defenses. DeviceManager relies on Web3/blockchain-based Command-and-Control (C2) resolution and DNS tunneling for data transport. It resolves its actual C2 server dynamically via the blockchain, a technique known as EtherHiding.

DeviceManager collects extensive system telemetry, including OS version, architecture, machine GUID, hostname, username, antivirus status, domain, and more. DeviceManager supports three command interpreters (CMD, PowerShell, and Python) across two operational modes (in-memory and on-disk). When running in DNS mode, the RAT is hardcoded to execute payloads exclusively in memory. The malware also implements HTTP POST C2 communication and utilizes EtherHiding for resilient C2 infrastructure resolution. DOUBLECUP uses various techniques to evade detection, including reflective code loading, obfuscated files or information, environmental keying, deobfuscation of files or information, and masquerading.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The threat is a highly advanced malware campaign known as DOUBLECUP, which leverages ClickFix pages to deliver two payloads: an updated variant of CountLoader and a newly uncovered RAT named DeviceManager. The campaign demonstrates evasion at its core, utilizing steganography and environmental keying to bypass defenses. DeviceManager relies on Web3/blockchain-based Command-and-Control (C2) resolution and DNS tunneling for data transport. It resolves its actual C2 server dynamically via the blockchain, a technique known as EtherHiding.

DeviceManager collects extensive system telemetry, including OS version, architecture, machine GUID, hostname, username, antivirus status, domain, and more. DeviceManager supports three command interpreters (CMD, PowerShell, and Python) across two operational modes (in-memory and on-disk). When running in DNS mode, the RAT is hardcoded to execute payloads exclusively in memory. The malware also implements HTTP POST C2 communication and utilizes EtherHiding for resilient C2 infrastructure resolution. DOUBLECUP uses various techniques to evade detection, including reflective code loading, obfuscated files or information, environmental keying, deobfuscation of files or information, and masquerading.[emaillocker id="1283"]

The campaign delivers its payloads through phishing pages, compromised websites, and other means. The threat has been observed in multiple regions and has a significant impact on the security landscape. Security teams must prioritize behavioral analytics and telemetry-driven detections to stay ahead of custom loaders and emerging malware families.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1203 Exploitation for Client Execution -
Execution T1204.002 User Execution Malicious File
Persistence T1543.003 Create or Modify System Process Windows Service
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Defence Evasion T1574.001 Hijack Execution Flow DLL
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Execution E1204 User Execution
Command & Control B0030 C2 Communication
Command & Control E1105 Ingress Tool Transfer
Persistence F0012 Registry Run Keys / Startup Folder
Discovery E1082 System Information Discovery
Exfiltration E1020 Automated Exfiltration
Anti-Static Analysis E1027 Obfuscated Files or Information
Execution B0023 Install Additional Program
Impact B0022 Remote Access

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu