Actor Profile
DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since early June 2026. The service provides operators with licenses and a Go-based Windows GUI client to orchestrate campaigns that deliver malware via ClickFix social engineering lures. Core developers supply client agents that enable operators to create campaigns and embed malicious code in ClickFix landing pages. The operation is managed via a Telegram bot (@harrypoterlohBOT) operated by a threat actor named "johnnysilverhe," who also published a suspicious VS Code extension called Agent IDE. DOUBLECUP's infrastructure was exposed through an open directory at 213.139.77[.]109:9090 containing testing files and license panel data. The service enables multiple campaigns per license, with each license containing unique keys and metadata including client IP addresses, active days, labels, and versions.
TTPs (Tactics, Techniques, Procedures)
DOUBLECUP employs multi-stage infection chains beginning with ClickFix social engineering (T1204.001) via fake CRM login pages (NetSuite, Odoo, HubSpot, Salesforce) embedded with iframes. The first stage drops steganographic PNG images into browser cache (T1027.003), which contain hidden JavaScript, VBScript, or PowerShell payloads. The second stage uses environmental keying (T1480) with the victim's public IPv4 address as a cryptographic seed for a custom SHA-256 stream cipher in CTR mode with XOR operations, ensuring payloads only decrypt on intended targets. CountLoader establishes persistence via scheduled tasks (T1053.005) and LNK file modification (T1547.009), performs browser extension reconnaissance targeting cryptocurrency wallets, profiles systems for Signal desktop app, and connects to C2 infrastructure using EtherHiding techniques with HTTP or DNS tunneling (T1071.001, T1071.004). The malware can execute secondary payloads (T1059.001, T1059.005), download and extract archives, and perform anti-forensics cleanup (T1070).
Targets & Patterns
DOUBLECUP campaigns target users through fake CRM platform login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce. The focus on cryptocurrency wallet browser extension reconnaissance and Signal desktop app profiling suggests targeting of cryptocurrency users and privacy-conscious individuals. The cross-platform nature of CountLoader (Windows and macOS variants) indicates broad targeting across desktop operating systems. The use of professional business application lures (CRM platforms) suggests targeting of corporate users and business professionals who regularly access these services. The loader-as-a-service model enables diverse threat actors to conduct campaigns with varying objectives, making target selection dependent on individual operator goals rather than centralized DOUBLECUP direction.
Historical Context
DOUBLECUP is assessed to have been active since early June 2026, making it a relatively new LaaS operation. The service distributes CountLoader, which has received updates including new persistence mechanisms, browser extension auditing for cryptocurrency wallets, and cross-platform macOS variants. A previously undocumented RAT called DeviceManager is also delivered through this infrastructure. The discovery originated from SOCRadar's investigation of an exposed open directory containing DOUBLECUP license panel testing files. The threat actor "johnnysilverhe" managing the operation's Telegram bot has also published a suspicious VS Code extension (Agent IDE) in the official Microsoft marketplace, suggesting potential supply chain compromise attempts or additional distribution vectors beyond the documented ClickFix campaigns.
Defensive Recommendations
- Monitor for suspicious clipboard operations and PowerShell/VBScript execution following browser activity, particularly commands that search browser cache directories (T1059.001, T1059.005)
- Implement network detection for steganographic image downloads followed by script execution, and inspect PNG files retrieved from suspicious domains for embedded payloads (T1027.003)
- Detect scheduled task creation and LNK file modifications targeting browser shortcuts, especially those that append additional execution parameters (T1053.005, T1547.009)
- Block or monitor connections to the identified infrastructure (213.139.77[.]109:9090) and implement DNS tunneling detection for unusual query patterns (T1071.004)
- Audit browser extensions regularly and alert on reconnaissance activity targeting cryptocurrency wallet extensions or Signal desktop app enumeration
---
# Geopolitical Context
Geopolitical Context
The emergence of DOUBLECUP represents the continued maturation of Russia-linked cybercrime-as-a-service ecosystems, where sophisticated loader infrastructure is commoditized for use by multiple operators. The service's licensing model, client management tools, and Telegram-based command infrastructure are consistent with Russian-language underground markets that have historically operated with relative impunity within Russian jurisdiction. The targeting of enterprise CRM platforms (NetSuite, Salesforce, HubSpot, Odoo) through credential-harvesting lures suggests a focus on business email compromise (BEC) and financial fraud vectors, aligning with profit-driven cybercrime rather than state-sponsored espionage. However, the dual-platform capability (Windows and macOS), advanced anti-analysis techniques including environmental keying, and focus on cryptocurrency wallet reconnaissance indicate a professionally developed toolset that could serve multiple threat actor types. The operation's infrastructure—including an exposed license panel and public Telegram bot—demonstrates operational security lapses typical of mid-tier cybercrime groups, though the technical sophistication of the steganographic delivery mechanism and custom encryption schemes suggests capable developers.
State Actor Alignment
DOUBLECUP is assessed to be a Russian-origin cybercrime service based on its operational infrastructure, though no direct state sponsorship is evident from available reporting. The service operates as a commercial loader-as-a-service platform, suggesting profit motivation rather than strategic intelligence collection. Russian authorities have historically shown limited interest in prosecuting cybercrime operations that target foreign entities, particularly Western commercial organizations, creating a permissive environment for such services. The lack of targeting against Russian or CIS entities—a common characteristic of Russia-based cybercrime groups operating under informal understanding with domestic law enforcement—may be present but is not explicitly documented in available data. No sanctions designations or formal attributions to Russian state agencies (GRU, FSB, SVR) are reported. The service's availability to multiple licensed operators increases the risk of use by actors with varying motivations, potentially including those with state nexus, though current evidence points to financially motivated cybercrime as the primary use case.
Business Impacty pro region
The DOUBLECUP campaign's impersonation of widely used enterprise CRM platforms poses significant risk to organizations across North America and Europe, where these services maintain dominant market share. The dual-platform capability targeting both Windows and macOS environments expands the threat surface beyond traditional Windows-centric malware, reflecting growing attacker interest in Apple's expanding enterprise footprint. European organizations face particular exposure given GDPR compliance requirements and the potential for credential theft leading to data breach notifications and regulatory scrutiny. The cryptocurrency wallet reconnaissance functionality suggests targeting of fintech sectors and individual users engaged in digital asset management, relevant across all developed economies. The loader-as-a-service model enables geographic distribution of threat activity, as multiple operators can deploy campaigns tailored to specific regional targets using shared infrastructure. NATO member states and EU institutions should anticipate continued use of such Russian-origin cybercrime infrastructure against commercial and potentially governmental targets, particularly as geopolitical tensions persist following Russia's invasion of Ukraine. The service's commoditization lowers barriers to entry for less sophisticated actors, potentially increasing overall threat volume across transatlantic digital infrastructure.
Forecast
If DOUBLECUP operators maintain current operational security practices—including exposed infrastructure and public Telegram channels—law enforcement disruption becomes increasingly feasible within 3-6 months, particularly if Western agencies coordinate takedown efforts with hosting providers. However, if the service's developers address these security gaps and migrate to more resilient infrastructure, the platform may persist and expand its operator base throughout 2026. Should additional payloads beyond CountLoader and DeviceManager be integrated—particularly ransomware or banking trojans—the service's impact on enterprise targets is likely to escalate significantly. If Russian authorities continue their non-intervention posture toward cybercrime targeting Western entities, similar LaaS platforms will likely proliferate, further commoditizing advanced delivery techniques like steganography and environmental keying. Organizations that fail to implement robust email security, browser isolation, and user awareness training around ClickFix social engineering are likely to experience continued compromise. If the threat actor "johnnysilverhe" and the suspicious VS Code extension "Agent IDE" are confirmed as supply chain attack vectors, developer communities may face a new wave of IDE-based compromise attempts. Defensive measures including browser cache monitoring, detection of steganographic image retrieval patterns, and network-based identification of environmental keying behaviors will become increasingly critical if this delivery methodology is adopted by additional threat groups.
