THREATOPS
THREAT OPSThreat News › Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs

Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs

medsocradar_blogPublished 2026-08-03

<h1>Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs</h1> <p>SOCRadar’s Threat Research Unit (STRU) identified and analyzed <strong>DOUBLECUP</strong>, a <strong>Russian Loader-as-a-Service (LaaS)</strong> for <a href="https://socradar.io/blog/clickfix-filefix-copy-paste-top-social-engineering/">ClickFix</a> campaigns. Operating in a client-server architecture

Attributed threat actors

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/