Russian-Linked Doublecup Malware Infiltrates Windows, macOS via Browser Caches
Cybersecurity researchers have discovered a sophisticated new Loader-as-a-Service (LaaS) platform called DOUBLECUP that is using ClickFix attacks to infect Windows and macOS systems. The Russian-linked operation, which began in early June 2026, offers cybercriminals a subscription-based service with ready-made attack infrastructure and licensing.
The platform hosts steganographic PNG images containing hidden malicious code and manages encryption keys, session endpoints, payload generation and rebuilding. This service-based model enables even less experienced threat actors to launch highly sophisticated malware campaigns with minimal technical expertise.
DOUBLECUP operates by hiding malware inside PNG images stored in victims’ browser caches. The attack begins when users visit fake login pages impersonating trusted online services such as NetSuite, Odoo, HubSpot or Salesforce. These websites display fraudulent CAPTCHA verification prompts while secretly forcing the victim’s browser to download and cache a malicious PNG image.
The malware collects extensive information about compromised systems, including cryptocurrency wallet applications, browser extensions, and Signal Desktop installations. It establishes persistence using scheduled tasks on Windows or LaunchAgent services on macOS and can also download and execute additional payloads.