THREAT OPS › Threat News › Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
<h1>Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs</h1> <p>SOCRadar’s Threat Research Unit (STRU) identified and analyzed <strong>DOUBLECUP</strong>, a <strong>Russian Loader-as-a-Service (LaaS)</strong> for <a href="https://socradar.io/blog/clickfix-filefix-copy-paste-top-social-engineering/">ClickFix</a> campaigns. Operating in a client-server architecture
Attributed threat actors
- Sea TurtleG1041
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
- Windows Management InstrumentationT1047
- System Owner/User DiscoveryT1033
- Create or Modify System ProcessT1543
- Permission Groups DiscoveryT1069
- DNST1071.004
- Boot or Logon Autostart ExecutionT1547
- Symmetric CryptographyT1573.001
- Browser ExtensionsT1176.001
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Scheduled Task/JobT1053
- Native APIT1106
- Deobfuscate/Decode Files or InformationT1140
- MasqueradingT1036
- Reflective Code LoadingT1620
- Shortcut ModificationT1547.009
- System Network Configuration DiscoveryT1016
- Command and Scripting InterpreterT1059
- File and Directory DiscoveryT1083
- Web ServiceT1102
- Execution GuardrailsT1480
- User ExecutionT1204
- Windows Management Instrumentation Event SubscriptionT1546.003
- PowerShellT1059.001
- Local GroupsT1069.001
- Unix ShellT1059.004
- Inter-Process CommunicationT1559
- Obfuscated Files or InformationT1027
- Event Triggered ExecutionT1546
- Encrypted ChannelT1573
- Rename Legitimate UtilitiesT1036.003
- SteganographyT1027.003
- Query RegistryT1012
- Security Software DiscoveryT1518.001
- PythonT1059.006
- Launch AgentT1543.001
- Windows Command ShellT1059.003
- Web ProtocolsT1071.001
- Malicious Copy and PasteT1204.004
- Software DiscoveryT1518
- Ingress Tool TransferT1105
- SteganographyT1001.002
- Environmental KeyingT1480.001
- Dead Drop ResolverT1102.001
- Command and Scripting InterpreterAML.T0050
- MasqueradingAML.T0074
Indicators of compromise
- 882914f9014f14e89123e835f103ac8f9d4b2e358c1f21c1cbc7f1054e6afed6sha256
- 8585721cbc46780903bd727e37a9ed07a33463852046ff65bc718ded4c80dfb1sha256
- 28cbbca8099bb1b27668d135314842c69ceb478a7d6b4b08f063d106a06c8f9dsha256
- 6e08cb5602f63bee2b40739167b4aef77763bc8fb47b4839ca2fc1607ad35cbasha256
- ea70895620f955b0712b85c3fee41de7437d5068267966f0b4fb6fa2704c3a50sha256
- bdf28e611d77362c40a0445655a35943c03accf21bb9a5af755da7eac5ea5e40sha256
- afe273533d6f9d0b8852988f6a4b34571dd52af4c690e54723a86257aa8a015dsha256
- 08730fda7366104b1461b12834f55723381bf34a234947689c708b1ee431af69sha256
- 0xc027490af56a9d7050fc259ecd03da1580b84aaeeth
- 0xc027490AF56a9d7050fc259Ecd03DA1580b84aaeeth
- 0xCE17b1EF00d47105Bc127BbE6fC45dE47BC22fb8eth
- https://urlscan.io/result/019f57c1-ef15-73ff-9660-d16363fe8f6b/url
- https://www.virustotal.com/gui/file/882914f9014f14e89123e835f103ac8f9d4b2e358c1f21c1cbc7f1054e6afed6/url
- https://{domain}/{slug}/api/configurl
- https://marketplace.visualstudio.com/items?itemName=johnnysilverhe.agent-ideurl
- https://urlscan.io/search/#canva-arts.comurl
- https://urlscan.io/result/019eec1e-be50-753c-a9d9-015ccd84ef71/dom/url
- https://app.any.run/tasks/90b8aecf-eb5b-4b7f-ba91-b19d6f815a94url
- https://www.cyderes.com/howler-cell/acr-stealer-rides-on-upgraded-countloaderurl
- https://www.silentpush.com/blog/countloader/url
- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/sinkholing-countloader-insights-into-its-recent-campaign/url
- https://…”url
- https://app.any.run/tasks/39e3f70a-cf6b-434c-8f44-0231f60e0caburl
- https://sepolia.etherscan.io/address/0xc027490af56a9d7050fc259ecd03da1580b84aae#codeurl
- https://sepolia.etherscan.io/tx/0x64be402ed425c0a6e5ff4fb9e2c9620766b4e53c745e7bb3514d5facc6355646url
- 213.139.77.109ipv4
- 67.219.107.181ipv4
- 91.92.240.100ipv4
- 1.5.0.0ipv4
- 80.96.109.229ipv4
- 167.148.201.131ipv4
- 89.124.117.12ipv4
- 103.22.137.227ipv4
- 146.70.124.154ipv4
- ip-api.comdomain
- srv641398444.host.ultaserver.netdomain
- nxtdrcliam.sitedomain
- cloud-electronic.comdomain
- cloudscraft.comdomain
- examcanvas.comdomain