๐ต๏ธ RESEARCH & DEEP DIVES
- DOUBLECUP Appends a PowerShell Payload to PNG Files
DOUBLECUP uses PNG files to deliver a PowerShell payload.- ClickFix campaign operators use DOUBLECUP, a Russian loader-as-a-service active since June 2026.
- Campaigns deliver CountLoader variants for Windows and macOS plus the DeviceManager RAT.
- DOUBLECUP appends a cleartext PowerShell script after a PNG file rather than hiding it in image pixels.
- The script uses FINDSTR to extract the appended payload before passing it to PowerShell.
- DeviceManager uses EtherHiding and communicates with command-and-control servers over HTTP or DNS tunneling.
๐ Coverage: socradar.io ยท ๐ via SANS ISC
๐ ADVISORIES
- ๐ Source for Trojanized npm Packages Deliver RedC2 4.0 Linux Implant โ trendaisecurity.com
๐ CVEs & KEV
- CVE-2026-78168 โ CVSS 8.9 โ EFM ipTIME T24000M Critical Improper Authentication (CVE-2026-78168)