THE article discusses a new malware identified as DOUBLECUP, which employs a PNG file for its payload. Although initially intriguing for its use of steganography, the author, Didier Stevens, notes that the malware does not actually conceal its PowerShell script within the PNG image. Instead, the script is appended after the PNG file. Stevens highlights a clever method through which the script can be extracted using the FINDSTR command in Windows, which leverages a specific line break format in the script. The blog post was published and last updated on August 24, 2026.
Malware DOUBLECUP exploits PNG file to sneak PowerShell payload
CyberSIXT Evidence Panel
Source marked as original reporting
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Malware DOUBLECUP exploits PNG file to sneak PowerShell payload
isc.sans.edu
-
DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT
securityonline.info
-
DoubleCup RAT Leverages ClickFix and PNG Cache to Evade Defences
thehackernews.com