# Your Browser's Cache Is Now a Malware Staging Ground


Russian cybercriminals have spent years iterating on delivery mechanisms, and DOUBLECUP represents their latest refinement: a loader-as-a-service that buries its payload inside PNG images sitting in your browser's own cache, invisible to most endpoint defenses and nearly indistinguishable from legitimate web traffic.


The technique is clever in the way that genuinely worrying things tend to be.


## ClickFix Does the Heavy Lifting


Before DOUBLECUP can do anything exotic, it needs the user to act. That's where ClickFix comes in — a social engineering method that's become the preferred initial-access play for several Russian-linked crews over the past 18 months. The victim lands on a compromised or attacker-controlled page, sees a convincing fake CAPTCHA or browser error, and is instructed to press a keyboard shortcut and paste a command into their own system. No exploit required. No zero-day burned.


ClickFix works because it outsources the payload execution to the user. Security tools that would flag a downloaded executable often have nothing to detect until the PowerShell session is already running. The social engineering framing — "your browser needs updating," "verify you're not a robot" — has gotten polished enough that even technically aware users have reported being briefly fooled.


DOUBLECUP pairs this entry vector with something harder to detect once the user has been convinced.


## Images That Aren't Just Images


The loader's signature move is encoding malicious content inside PNG files, which browsers then cache locally. When the victim's machine later retrieves those images — as part of ordinary web browsing — the hidden payload gets extracted and executed. From the perspective of network monitoring tools, the traffic looks like ordinary image loading. From the perspective of a browser cache inspection, the files look like pictures.


This is steganography as an operational tradecraft choice, not a novelty. Threat actors have used image-based payloads before, but embedding them in files the victim's own browser caches and trusts is a meaningful evolution. It sidesteps download warnings, bypasses content filters that inspect files based on extension or MIME type, and puts the staging environment on the victim's own disk in a location most EDR tools don't deeply scrutinize.


The files stay in cache. If the initial compromise goes undetected for long enough, the organization may never trace back the exact delivery mechanism.


## What Gets Dropped


DOUBLECUP's confirmed payloads reveal something about its intended customer base. CountLoader hits both Windows and macOS — an increasingly common design choice that signals these services are selling to operators with varied targets, not just Windows-focused ransomware affiliates. Cross-platform support costs development effort; someone decided that effort was worth it.


For Windows victims, there's an additional payload: DeviceManager, a remote access trojan that appears to be purpose-built for this service. RATs new enough to lack detection signatures are valuable commodities in the underground ecosystem. DOUBLECUP isn't just selling delivery — it's selling the whole chain, including a payload with a fresh evasion shelf life.


The loader-as-a-service model matters here. Operators who lack the technical sophistication to build their own delivery infrastructure can rent DOUBLECUP's, focus on the initial luring and victim selection, and receive working shells on compromised machines. This is the commoditization of intrusion that's driven ransomware's explosion, applied now to more targeted campaigns.


## HackWire Analysis


DOUBLECUP arrives at a moment when ClickFix has reached something like critical mass among initial-access brokers. The technique appeared in Scattered Spider campaigns, in phishing waves targeting financial services, and in at least three documented campaigns against European government entities in 2025. It's proliferated because it works, and now a dedicated LaaS has been built around it.


What's easy to miss in coverage of this specific loader is the structural shift it represents. When browser cache becomes a reliable staging area, defenders have to rethink what "clean" looks like. A machine with no suspicious executables in user-accessible directories can still be compromised via images sitting in %AppData%\Local\[Browser]\User Data\Default\Cache. Most organizations don't have tooling tuned to watch that.


The cross-platform payload is also a signal. Historically, macOS coverage in Russian cybercriminal tooling was an afterthought. CountLoader's macOS support suggests the operators or their customers have moved upmarket — corporate macOS environments, developer machines, finance and legal staff who tend to run Macs. Those targets carry higher-value credentials and often receive lighter endpoint scrutiny.


For defenders: ClickFix campaigns are detectable at the network perimeter if you're logging PowerShell invocations and watching for base64-encoded commands spawned from browser processes. The browser cache vector is harder — runtime monitoring of cache directories for executable content extraction is non-trivial, but behavioral rules around images spawning child processes or writing to unusual locations are feasible with modern EDR. The real gap is that most organizations aren't looking there at all.


The underground market for DOUBLECUP access will grow until detection catches up. It hasn't yet.


— HackWire Editorial


## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)