DeviceManager is a modular Python-based remote access trojan distributed via DOUBLECUP. It uses EtherHiding to resolve C2 servers via Ethereum/Polygon smart contracts and communicates over HTTP or DNS tunneling. It avoids CIS language locales and can execute PowerShell and Python scripts.