DOUBLECUP: the Russian service using browser cache to inject malware without touching the disk
DOUBLECUP is a Russian loader-as-a-service using fake CAPTCHAs, steganography, and browser cache to deploy fileless malware like CountLoader and RATs.
Illustrative image generated with AI
Discovered on August 3, 2026, DOUBLECUP is a Russian-origin loader-as-a-service active since early June. It combines ClickFix techniques, steganography on PNG images, and fake CAPTCHAs to load malicious code directly from the browser cache. The service distributes two distinct families – an updated CountLoader and the new DeviceManager RAT – and provides criminals with a Go application to manage campaigns, infrastructure, and automatic payload reconstruction. Impact is high: credential theft, sensitive data exfiltration, and persistence on Windows and macOS, all with a decentralized, blockchain-based C2.
Fake CAPTCHAs, iframes, and steganography: the infection chain
The attack starts from a spoofed login page impersonating NetSuite, Odoo, HubSpot, or Salesforce. An iframe loaded in the page deposits a seemingly harmless PNG image in the browser cache. Hidden inside those pixels is the malicious code, encoded with a steganographic technique that keeps it invisible to casual inspection.
To “pass” the CAPTCHA, the victim is asked to paste and run a command already placed in the clipboard (Win+R, Paste, Enter). The command calls findstr or certutil to extract the concealed content from the cached image, typically located in paths like %LocalAppData% or AppData\Local\Microsoft\Edge\User Data. No executable is written to disk: a second-stage fileless dropper decrypts the final payload only after verifying its integrity via a SHA-256 hash, and launches it directly in memory.
The two payloads: CountLoader and DeviceManager
CountLoader exists in Windows and macOS versions. It steals system information (GUID, SID, hostname, installed software, running antivirus) and locates cryptocurrency wallets as well as the Signal Desktop application. It gains persistence through scheduled tasks (Windows) or LaunchAgents (macOS). It can download and execute MSI packages, PowerShell modules, and DLLs, opening the door to ransomware or other loads. The macOS variant uses system utilities like sw_vers, system_profiler, and ioreg to collect data.
DeviceManager is a modular RAT written in Python, active only on Windows and configured not to run in CIS countries. It retrieves the command-and-control server’s IP address via smart contracts on Ethereum or Polygon – a technique known as EtherHiding – and then communicates through A and TXT DNS records. Its modular architecture allows different remote control functions to be activated depending on the objectives.
Paid infrastructure and blockchain C2
DOUBLECUP is a professional service. Customers receive a Windows application developed in Go to build customized campaigns. The service manages the hosting of steganographic images, session endpoints, cryptographic keys, and automatic payload reconstruction. The identified infrastructure traces back to IP address 213.139.77.109. The use of smart contracts for C2 pointers and DNS records for actual traffic makes both disruption and tracking difficult.
How to defend yourself
- Train users never to execute commands pasted from web pages, especially in the presence of a fake CAPTCHA.
- Monitor and block abnormal use of
findstrandcertutilon files from browser cache folders. - Filter traffic to IP 213.139.77.109 and to the C2 domains listed in the indicators of compromise.
- Configure EDR/XDR solutions with rules to detect suspicious processes launched from paths like
%LocalAppData%\Microsoft\Edge\User Data. - Restrict execution of unsigned scripts and enable application control to prevent foreign code from running.
Sources
This article is an original reworking based on the sources below.




