DOUBLECUP는 ClickFix를 사용하여 감염된 PNG 이미지를 통해 RAT를 배포합니다.
새로운 러시아의 로더 서비스 DOUBLECUP는 ClickFix 유인책을 사용하여 피해자의 브라우저 캐시에 악성 PNG 이미지를 스테이징합니다. 이후 이 이미지를 통해 CountLoader 및 DeviceManager라는 원격 접근 트로이 목마를 배포합니다. 이 과정에서 스테가노그래픽 PNG 이미지가 브라우저의 캐시에 저장되고, 숨겨진 내용이 검색되어 실행됩니다.
DOUBLECUP uses ClickFix to stage malware-laden PNGs to deliver RAT.
The new Russian loader-as-a-service, DOUBLECUP, employs ClickFix lures to stage malware-laced PNG images in victims' browser cache. This process allows the delivery of CountLoader and a previously undocumented remote access trojan, DeviceManager. The initial stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes it.