DOUBLECUP Uses Blockchain Contracts to Conceal New RAT
ClickFix is a social-engineering technique that presents fake verification or troubleshooting prompts and persuades users to paste attacker-supplied commands into Windows. DOUBLECUP turns that playbook into a Loader-as-a-Service offering, lowering the technical bar for malware operators. Its use of browser-cached images to stage code and public blockchains to resolve command-and-control infrastructure matters because both tactics weaken conventional domain blocking and frustrate sandbox-based analysis.
SOCRadar’s Threat Research Unit disclosed on Aug. 3, 2026, that DOUBLECUP had been active since at least June, using counterfeit NetSuite, Odoo, HubSpot and Salesforce pages to distribute CountLoader v4.5p and a previously undocumented DeviceManager remote-access Trojan. DeviceManager queries smart contracts on Ethereum and Polygon for its C2 address, then uses DNS tunneling disguised as microsoft.com subdomains. CountLoader, meanwhile, runs briefly on a 25-minute cycle, reducing the behavioral footprint that endpoint defenses can observe.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.