software · · 2 min read

New Russian Malware Service Uses Tricky Image Files

By Rachel Lin

New Russian Malware Service Uses Tricky Image Files

Hidden Threats in Plain Sight

A new Russian cybercrime operation, dubbed DOUBLECUP, is deploying sophisticated malware. It uses fake browser updates to trick users. This method allows them to hide malicious code within image files. The ultimate goal is to install dangerous software like CountLoader and a new remote access trojan called DeviceManager.

This advanced technique involves a two-stage attack. First, victims are lured by fake ClickFix browser update prompts. These prompts are designed to look legitimate.

When a user clicks on the fake update, a malicious PNG image is downloaded. This image is not what it seems. It contains hidden code that exploits a vulnerability in the browser's cache. The image then stages the next phase of the attack.

How Does This Malware Evade Detection?

The hidden code within the PNG image then extracts and executes the actual malware. This process is designed to be stealthy. It bypasses many traditional security measures.

The use of cached PNGs is particularly insidious. It allows the attackers to store malicious payloads directly on the victim's system. These files are often overlooked by security software. The malware then loads from these seemingly harmless image files. This makes detection and removal much harder for the average user.

Once installed, CountLoader can download additional malicious programs. DeviceManager, the newly identified remote access trojan, gives attackers full control over the compromised device. This allows for data theft, surveillance, and further attacks. Users should be extremely cautious about unexpected browser update requests.

Frequently Asked Questions

What is DOUBLECUP? DOUBLECUP is a new Russian loader-as-a-service (LaaS). It provides cybercriminals with tools to deliver malware using deceptive tactics. This service makes it easier for various threat actors to launch attacks.

How does ClickFix lure victims? ClickFix lures appear as legitimate browser update prompts. They trick users into clicking on them, initiating the download of malicious files. These prompts often mimic well-known browser interfaces.

What is DeviceManager? DeviceManager is a previously undocumented remote access trojan (RAT). It grants attackers extensive control over a compromised computer. This control can be used for data exfiltration and system manipulation.

More stories:

Content written by Rachel Lin for techbriefe.com editorial team, AI-assisted.

Share:

Leave a comment