HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

DOUBLECUP Loader‑as‑a‑Service Uses Steganographic PNGs to Deploy CountLoader & DeviceManager RAT

A Russian threat group named DOUBLECUP is delivering malware via steganographic PNGs cached in browsers, highlighting gaps in web‑gateway filtering and the importance of SOC 2 access‑control evidence. Organizations must ensure continuous monitoring and security‑awareness training to meet audit requirements.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
thehackernews.com

DOUBLECUP Loader‑as‑a‑Service Uses Steganographic PNGs to Deploy CountLoader & DeviceManager RAT

What Happened — A Russian‑origin threat group dubbed “DOUBLECUP” is operating a loader‑as‑a‑service (LaaS). The first stage drops a PNG image containing hidden malicious code into a victim’s browser cache (ClickFix lure). When the browser later retrieves the cached image, the embedded payload is extracted and executes a second‑stage loader that delivers the CountLoader malware and a previously unknown Remote Access Trojan named DeviceManager.

Why It Matters for Compliance & Audit Readiness

  • The technique sidesteps traditional file‑scan controls, underscoring the need for SOC 2 Access Controls that enforce strict web‑gateway filtering and continuous monitoring of browser‑cache activity.
  • A successful RAT infection can lead to unauthorized data access, making evidence of Security Awareness Training and documented phishing‑defense policies essential for a defensible audit trail.
  • Continuous evidence collection (e.g., logs of blocked malicious content) satisfies the SOC 2 CC6.1 “System Monitoring” requirement and demonstrates due diligence to regulators and customers.

Who Is Affected — Enterprises across all sectors that allow employee web browsing on corporate devices, especially those with SaaS‑based productivity suites and remote‑work environments.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 (System Monitoring) and CC6.2 (Security Incident Management) controls; ensure logs of web‑gateway and endpoint activity are retained and reviewed.
  • Verify that phishing‑simulation and security‑awareness programs cover steganographic content and cache‑based delivery techniques.
  • Deploy or tighten web‑proxy and endpoint protection rules that inspect cached objects for hidden payloads.

Source: The Hacker News

Technical Notes

  • Attack vector: Phishing lure (ClickFix) → steganographic PNG in browser cache → RAT delivery.
  • No public CVE; the threat relies on abuse of standard PNG handling and browser caching mechanisms.
  • Payloads: CountLoader (loader) and DeviceManager (remote‑access trojan) capable of credential theft, data exfiltration, and lateral movement.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →