DOUBLECUP ClickFix Loader-as-a-Service (CountLoader / DeviceManager RAT)
Rented ClickFix delivery service active since June 2026. Operators embed a fixed frontend snippet into their own lure pages; DOUBLECUP hosts the steganographic PNG, the session endpoints and the encryption keys. Stage 1 is a clipboard command that finds the cached PNG by exact file size and carves an embedded script out of it, so nothing is downloaded at execution time. Stage 2 derives its decryption key from the victim's public IP, meaning the payload will not decrypt in an offline sandbox. Observed payloads: CountLoader 4.5p (Windows PowerShell and macOS Mach-O) and DeviceManager, a Python RAT that resolves C2 from Ethereum/Polygon smart contracts (EtherHiding) and tunnels over DNS using microsoft.com as a decoy apex.
Anchors
ip:213.139.77.109 OR ip:80.96.109.229 OR ip:167.148.201.131 OR ip:89.124.117.12 OR ip:103.22.137.227 OR ip:67.219.107.181 OR ip:146.70.124.154 OR ip:91.92.240.100 OR domain:srv641398444.host.ultaserver.net OR domain:*nxtdrcliam.siteProvenance
Sightings (0)
No sightings recorded yet.