Victim-Tied Payloads Undercut Sample-Based Hunting

DOUBLECUP makes the payload change with the victim, so the usual habit of catching one sample and matching it across the fleet breaks down. The lure is just the front end; the hidden stage is decrypted in memory with a key tied to the victim’s public IP, so copied cache artifacts do not give you the same malware back. SOCRadar says the service has been active since early June 2026 and uses ClickFix-style prompts to stage disguised PNGs in browser cache before delivering CountLoader variants for Windows and macOS, plus a previously undocumented RAT called DeviceManager. DeviceManager uses EtherHiding for C2 and can communicate over HTTP or DNS tunneling. That design leaves defenders with less reusable malware to hash, sandbox, or signature-match. One recovered blob may tell you the campaign exists, but not give you a stable artifact for the next victim.

Part of the PlainSec briefing for 2026-08-04

Every edition of this story: Victim-Tied Payloads Undercut Sample-Based Hunting

Sources