CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

DOUBLECUP: A New Russian Loader-as-a-Service

August 4, 2026

DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since June 2026. It uses ClickFix lures and steganographic PNG images to deliver malware like CountLoader and DeviceManager. Operators use a Go-based client with license keys and a Telegram bot for management.