# Your Browser Cache Is Now a Malware Staging Area
The login page looks right. The URL is close enough. You type your Salesforce credentials, get a popup telling you to run a quick verification command, and paste it into your terminal without thinking twice. That's the moment DOUBLECUP owns you — and it does it in a way that most endpoint defenses won't catch, because the payload never touches disk in any form that looks like malware. It was hiding in your browser cache as a PNG.
SOCRadar published their technical analysis of DOUBLECUP this week, and it's one of the more inventive malware architectures to surface this year. The operation has been running since at least early June 2026 as a structured loader-as-a-service: Russian developers, licensed operators, campaign infrastructure, and a Telegram bot that tracks infections in real time. What sets it apart from the crowded ClickFix imitator market is the kill chain's technical core — specifically, what happens to a victim's browser after they paste that command.
## The Cache-as-Payload Trick
Most browser-based malware delivery relies on downloads the user can see, or injected scripts that endpoint tools can hook. DOUBLECUP sidesteps both by forcing the browser to prefetch a steganographic PNG — an image that passes visual inspection but conceals malicious JavaScript, VBScript, or PowerShell in its pixel data. The image lands in the browser's local cache through an entirely legitimate browser prefetch operation. No file dialogue, no suspicious download event.
The ClickFix command the victim pastes then retrieves and decodes that cached image, extracts the hidden payload, and executes the second stage entirely in memory.
The second stage is where the real engineering shows: DOUBLECUP decrypts its final payload using a custom SHA-256 stream cipher in Counter (CTR) mode, XOR'd against the victim's public IP address as the key. That's not accidental cleverness — it's a deliberate sandbox-evasion technique. Automated analysis environments almost universally run behind shared, datacenter IP blocks. When a DOUBLECUP sample runs in a sandbox and produces the wrong IP-derived key, the payload decrypts to garbage. Analysts see noise. The actual victim gets CountLoader and DeviceManager RAT.
## CRM Impersonation and the Target Profile
The campaigns SOCRadar tracked have consistently impersonated business CRM platforms: NetSuite, Odoo, HubSpot, Salesforce. That's not a random selection. These are platforms where a single set of stolen credentials grants access to customer contact lists, deal pipelines, billing records, and internal communications. The target profile here is the mid-market business user — likely in sales or ops — who uses one of these platforms daily and wouldn't think twice about a re-authentication prompt.
Delivery happens through bogus login pages with embedded iframes that serve the ClickFix lure. The infrastructure generates browser-specific commands via a configuration endpoint, correctly matching payloads to Chrome, Edge, Firefox, Brave, and Opera. The operator's license panel handles the campaign orchestration; each license tracks IP metadata, active campaign days, and version info. Multiple simultaneous campaigns per license are supported.
A Telegram bot — @harrypoterlohBOT, managed by an actor using the handle "johnnysilverhe" — handles real-time infection callbacks, key delivery, and command routing. The same handle is tied to a VS Code extension called Agent IDE, currently listed in Microsoft's official marketplace. The extension hasn't been confirmed malicious by Microsoft at time of publication, but the overlap is notable: if your development tooling is compromised by the same actor running your RAT's C2, any air-gapping assumptions about network segmentation become irrelevant.
## DeviceManager's Blockchain C2
The final payload, DeviceManager RAT, uses EtherHiding to locate its command-and-control infrastructure. EtherHiding stores C2 addresses in blockchain transactions — typically on Binance Smart Chain — rather than in hardcoded domains or traditional DNS. This is meaningful operationally: you can't sinkhole a blockchain record the way you'd sinkhole a domain. Defenders can block known C2 IP addresses, but operators can rotate by writing new values to the chain. Communication falls back to DNS tunneling if HTTP is blocked, making network-level detection substantially harder.
CountLoader, DOUBLECUP's other delivered payload, has been compiled for both Windows and macOS — an increasingly common pattern as threat actors recognize that the enterprise Mac fleet has grown significantly over the last five years and remains under-defended relative to Windows environments.
## OPSEC Failure That Blew the Whole Thing Open
What kicked off SOCRadar's investigation wasn't a breakthrough in malware analysis — it was an open directory. The threat actors left testing files publicly accessible at 213.139.77[.]109:9090, which led researchers directly to the DOUBLECUP license panel and exposed the operation's infrastructure in detail.
This is a recurring theme in LaaS busts. The developers build sophisticated evasion into the payload chain, then leave their admin panel unprotected because setting up proper authentication on internal tooling feels like friction. The operational sophistication of the malware does not correlate with the operational security of the people running it.
---
## HackWire Analysis
DOUBLECUP is significant for several reasons that the technical write-ups underweight.
The browser cache staging technique represents a meaningful evolution in fileless delivery. Security teams have spent years building detection logic around suspicious file writes, memory injection, and process hollowing. Staging through a browser's native prefetch mechanism — a legitimate operation indistinguishable from normal browsing activity in most EDR telemetry — exploits the blind spot created by that investment. Expect this technique to propagate to other malware families quickly once it's documented in criminal forums.
The IP-as-cryptographic-key design deserves more attention than it's getting. It's not just sandbox evasion — it means that every victim gets a unique payload decryption. Sharing a sample for analysis without the victim's IP at infection time renders it unanalyzable. This complicates incident response: forensics teams that pull the original binary from a compromised machine can't decrypt it without reconstructing the public IP state at the moment of infection. That's a meaningful gap in traditional IR playbooks.
The CRM targeting pattern fits a broader shift toward business process compromise over pure data exfiltration. Actors who own a Salesforce session can manipulate deals, reroute payments, and harvest contacts for spear-phishing downstream targets — all without triggering data loss prevention tools that are looking for bulk file transfers. The median time-to-detect for business email and CRM compromise remains measured in months, not days.
For defenders: prioritize ClickFix-variant detection rules in your SOC stack now. Block the execution of commands pasted from web clipboard events via PowerShell or cmd.exe. Review your browser cache forensics capability — most IR toolkits don't flag cached image analysis as a standard collection step, and they should. And if you have a VS Code extension policy, Agent IDE should be on your review list.
— HackWire Editorial
---