View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

DOUBLECUP Appends a PowerShell Payload to PNG Files

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • DOUBLECUP Appends a PowerShell Payload to PNG Files
    DOUBLECUP uses PNG files to deliver a PowerShell payload.
    • ClickFix campaign operators use DOUBLECUP, a Russian loader-as-a-service active since June 2026.
    • Campaigns deliver CountLoader variants for Windows and macOS plus the DeviceManager RAT.
    • DOUBLECUP appends a cleartext PowerShell script after a PNG file rather than hiding it in image pixels.
    • The script uses FINDSTR to extract the appended payload before passing it to PowerShell.
    • DeviceManager uses EtherHiding and communicates with command-and-control servers over HTTP or DNS tunneling.
      ๐Ÿ“Ž Coverage: socradar.io ยท ๐Ÿ‘ via SANS ISC

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Trojanized npm Packages Deliver RedC2 4.0 Linux Implant โ€” trendaisecurity.com

๐Ÿ”“ CVEs & KEV

  • CVE-2026-78168 โ€” CVSS 8.9 โ€” EFM ipTIME T24000M Critical Improper Authentication (CVE-2026-78168)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check