Palantir CEO Alex Karp on Monday once again warned that AI frontier labs are too untrustworthy for enterprises.
The CEO, who famously studied philosophy and earned a PhD in social theory, implied in Palantir’s quarterly shareholder letter that these were the kinds of capitalists who gave rise to Marxist socialism.
“There are Marxist overtones and undertones to our business,” he wrote in a letter to shareholders about Palantir’s outstanding quarter. “Others, including many of those building large language models, intend, knowingly or otherwise, to capture the means of production of their purported partners.”
To be clear, AI labs have hardly cornered Palantir out of the market. Quite the opposite. The skyrocketing use of AI helped Palantir achieve record-breaking results. For its second quarter, the company reported $1.9 billion in revenue, up 93% over the year-ago quarter, and $1.1 billion in profit, “more profit in a single quarter than we did in total revenue in the same period the year before,” he wrote.
Advertisement
During the quarterly conference call with Wall Street analysts, he explained his analogy further, relying heavily on a sort of “tech bro patriot” jargon common among defense tech companies. (Palantir’s senior leadership is entirely male.)
He asked on the call if companies are going “to buy into a future” where your job helps your “adversaries win, and everybody who does win is a small, tiny group of people living in a tiny place that somehow believe because they eat vegetables and they don’t support war fighters that they deserve to have the total means of production of this country? And the rest of us should just sit back and absorb the cost of that revolution, which we’re paying for.”
Palantir, in contrast, serves model-agnostic AI and analysis software to governments and enterprises, and allows organizations to control their data as well as their AI “exhaust,” aka, their prompts, orchestration, and context.
“How are we paying for it? In the enterprise context, people sign up for token self-pleasurings… at real cost like other forms of self pleasure,” he said. “You are paying for the right for them to migrate your IP, your know-how, your expertise to their model, so that they can build a competitive business that doesn’t require your business or people. And why are they doing it? It’s actually being done for what they believe are moral reasons. They are superior to you. They deserve to colonize your enterprise.”
Advertisement
Jarring language aside, he is making an underlying point that is increasingly being repeated elsewhere, including from the likes of Microsoft CEO Satya Nadella.
This theory points to the significant list of companies that partnered or paid for Anthropic and OpenAI while the AI labs launched similar businesses ranging from design tools to healthcare operations, legal, even drug discovery.
The truth is, none of these companies are economic villains or heroes — anymore than other for-profit companies are. AI is growing so quickly, the market changing so rapidly, there is clearly room for all, Palantir’s results show.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
John Ternus takes over as CEO of Apple on September 1, and he’s busy getting his executive team together. The latest addition is Laura Legros, retired VP of hardware engineering.
All eyes are on John Ternus as he prepares to replace Tim Cook as CEO of Apple. Very little is known about the enigmatic character beyond his accomplishments at Apple, but analysts are already looking for challenges he may face.
Every hire and leadership position is being scrutinized, and Bloomberghas learned the latest addition to team Ternus. Laura Legros is coming out of retirement to report directly to Ternus in a vice president role, though the name of her new position wasn’t shared.
She was previously a vice president of hardware engineering and worked for Ternus. All that was shared of her position was a fairly ambiguous statement that she would work “cross-functionally with different parts of the company.”
Advertisement
The only way to interpret that for now is to assume that she’ll be helping ensure the separate hardware teams aren’t too siloed in their operations. Johny Srouji is set to be the newly created Chief Hardware Officer, which means hardware engineering and hardware technologies are now under one leader.
While Legros will report directly to Ternus, it seems she’s likely to be structurally under Srouji as some kind of VP in hardware. Basically, even with the new leadership structure, Legros is back as a VP of hardware engineering, even if that wasn’t explicitly stated in the report.
For those keeping track, Legros was one of the executives that retired in 2022 and was included in Bloomberg‘s reporting about an executive exodus at Apple. No, not the current reportedly nightmare scenario, the previous one we were supposed to be concerned about.
Don’t expect John Ternus to suddenly change the face of Apple overnight, if ever. Some minor things might pop up in the first few months, but it’ll be hard to attribute any specific changes to Ternus or plans made under Cook for some time.
Chinese e-commerce and cloud giant Alibaba’s famed Qwen team of AI researchers last night unveiled Qwen3.8-Max, a new flagship 2.4-trillion-parameter mixture-of-experts (MoE) multimodal large language model (LLM) that targets one of the most competitive corners of the frontier AI market: autonomous software engineering and long-horizon enterprise work.
If the company’s published benchmarks hold up under broader independent testing, Qwen3.8-Max doesn’t merely compete with today’s leading proprietary models — it surpasses several of them on some key benchmarks in agentic computing.
Most notably, Qwen reports that Qwen3.8-Max scores 86.1 on the OSWorld-Verified benchmark measuring how well ahead of GPT-5.6 Sol Max (83.2) and Fable 5 (85.0), while also posting the highest reported score on PaperBench and leading or remaining highly competitive across software engineering, research reproduction, multimodal reasoning, and visual web development benchmarks.
The release also signals a potentially significant strategic shift for Alibaba: the company says open weights for Qwen3.8-Max will be released next week, alongside Qwen3.8-27B.
Advertisement
If that happens under a permissive license, it would represent the first time a Max-class Qwen model becomes available for self-hosted deployment—a move that could substantially reshape enterprise adoption.
One important caveat remains, however: Alibaba has not yet disclosed the licensing terms, leaving open the possibility that the release could use a more restrictive custom license, as we saw recently with Chinese rival Moonshot’s open Kimi K3 frontier model, rather than a broadly permissive one such as Apache 2.0.
A different definition of ‘frontier’
Over the past year, the competitive landscape for foundation models has become increasingly specialized.
OpenAI has largely focused its GPT series on general reasoning, multimodal interaction and enterprise productivity.
Advertisement
Anthropic’s Claude series has emphasized coding and dependable long-context reasoning. Google continues to push Gemini toward multimodal productivity and web-native workflows.
Moonshot AI’s Kimi K3 recently entered the conversation by pairing frontier-class performance with an open-weight release.
Qwen3.8-Max attempts to combine many of these strengths into a single model aimed squarely at enterprise automation.
Rather than emphasizing conversational intelligence, Alibaba is positioning the model as an autonomous coworker capable of executing projects that span days rather than minutes.
Advertisement
According to the company, Qwen3.8-Max can autonomously complete software projects lasting more than 10 days, reproduce research papers involving thousands of lines of code, perform iterative chip-design optimization, and continuously revise plans using multimodal feedback loops.
Those demonstrations remain company-produced and have not yet been broadly replicated by independent evaluators. Nevertheless, they illustrate a growing industry trend: frontier models are increasingly competing on their ability to finish entire workflows rather than answer individual prompts.
The benchmark suite released alongside Qwen3.8-Max reflects this shift.
Instead of focusing solely on traditional reasoning exams or coding puzzles, many of the highlighted evaluations measure long-horizon execution.
Advertisement
On OSWorld-Verified, which evaluates computer-use agents interacting with desktop environments, Qwen3.8-Max posts 86.1, ahead of GPT-5.6 Sol Max’s 83.2, Fable 5’s 85.0, and Gemini 3.1 Pro’s 76.2.
Qwen3.8-Max benchmark comparison bar chart. Credit: Alibaba Qwen
The model also leads:
PaperBench: 93.0
TerminalBench 2.1: 86.6
Vision2Web: 69.0
LVBench: 81.8
ERQA: 77.8
Elsewhere, it remains competitive with proprietary leaders while trailing in several categories.
Advertisement
On the professional software engineering benchmark SWE-Pro, for example, OpenAI’s model posts the highest reported score, while Opus 4.8 continues to lead on certain software engineering evaluations and Agents’ Last Exam.
Rather than dominating every benchmark, Qwen appears to offer one of the broadest balanced performance profiles currently available.
That balance may ultimately matter more for enterprise buyers than isolated benchmark wins.
Many organizations increasingly evaluate models based on how reliably they complete heterogeneous workflows—writing code, reading documents, navigating interfaces, generating reports, inspecting images and coordinating multiple subtasks—rather than optimizing for one narrow capability.
Advertisement
Where Qwen3.8-Max appears strongest
Assuming Alibaba’s published results translate into production deployments, several enterprise workloads stand out as particularly well suited for Qwen3.8-Max.
1. Long-running software engineering
Alibaba’s primary demonstration involves autonomous software development extending beyond ten days.
While enterprises should treat these demonstrations as vendor claims until independently reproduced, they align with a growing interest in persistent coding agents that operate continuously rather than interactively.
Advertisement
Organizations experimenting with autonomous engineering teams, CI/CD automation, repository maintenance, regression testing or feature implementation may find Qwen particularly attractive if its agentic performance proves consistent outside laboratory settings.
2. Computer-use agents
The strongest differentiator may be computer use.
OSWorld has rapidly become one of the industry’s most closely watched benchmarks because it measures a model’s ability to interact with operating systems instead of simply generating text.
Advertisement
Models capable of reliably navigating desktop software can automate countless repetitive business processes, including document processing, enterprise software integration, internal operations and legacy workflows where APIs may not exist.
Leading OSWorld could therefore translate into real operational advantages if benchmark performance generalizes to production environments.
3. Research automation
Qwen’s PaperBench leadership suggests strong potential for organizations performing scientific computing, literature review, experiment reproduction and technical analysis.
Advertisement
Research institutions, pharmaceutical companies and industrial R&D teams increasingly use LLMs not only for summarization but also for executing reproducible computational workflows. Models capable of maintaining context across extended sessions become increasingly valuable in these environments.
4. Multimodal industrial workflows
Unlike earlier multimodal systems that primarily analyze uploaded images, Qwen describes vision as an ongoing feedback mechanism integrated into planning and execution.
That architecture could prove particularly useful in manufacturing, logistics, engineering inspection and design review, where visual inputs continuously inform operational decisions rather than serving as isolated prompts.
Advertisement
The economics may prove just as important
Perhaps the biggest competitive pressure comes not from benchmark scores but from pricing through Qwen’s application programming interface (API) on QwenCloud (based in China):
Qwen3.8-Max launches at $2/$6 per million input/output tokens, a mid-priced model but undercutting the top U.S. proprietary offerings to which it is benchmarked against by meaningful percentages, less than 1/3 the combined in/out price of Claude Opus 5 and less than 1/4 the price of GPT-5.6 Sol Max.
Lower inference costs increasingly matter because agentic systems consume dramatically more tokens than conventional chatbots — a reality that likely factored into OpenAI’s decision late last week to cut the API prices of its mid- and lower-end GPT-5.6 lineup of models (Terra and Luna) by 20% and 80%, respectively.
Indeed, as those running these systems can attest, multi-hour autonomous workflows, iterative planning and continuous self-correction can generate millions of tokens during a single task.
Advertisement
For enterprises deploying hundreds or thousands of agents simultaneously, inference costs often become one of the largest operational expenses. Small reductions in per-token pricing therefore compound rapidly.
How it compares with American frontier models
Despite headline benchmark comparisons, Qwen3.8-Max should not necessarily be viewed as a wholesale replacement for leading American models.
Instead, its strengths suggest different deployment strategies.
OpenAI’s GPT family continues to excel as a broadly capable enterprise reasoning platform with mature tooling, ecosystem integration and extensive commercial deployment. Organizations already invested in Microsoft ecosystems or OpenAI’s enterprise offerings may continue to value those operational advantages even if Qwen leads on selected agent benchmarks.
Advertisement
Anthropic’s Claude Opus remains widely regarded as one of the strongest coding assistants, particularly for careful software engineering and long-context reasoning. Some enterprises may still prefer Claude for human-in-the-loop development where reliability and predictable behavior outweigh raw autonomy.
Google Gemini continues to differentiate itself through deep Workspace integration, multimodal capabilities and Google Cloud services, making it attractive for organizations already standardized on Google’s enterprise stack.
Where Qwen appears most compelling is for enterprises prioritizing autonomous execution, extended planning horizons and favorable inference economics without sacrificing frontier-level performance.
The open-weight question remains unanswered
The largest unknown surrounding Qwen3.8-Max has little to do with benchmarks.
Advertisement
Alibaba says open weights are coming next week. However, neither the announcement nor the provided documentation specifies the license that will govern those weights.
That distinction could prove critical.
A permissive license such as Apache 2.0 would significantly broaden enterprise adoption by allowing organizations to self-host, fine-tune and integrate the model into proprietary products with relatively few restrictions.
A custom license—similar to approaches used by several recent frontier releases—could impose limitations on commercial deployment, redistribution, field of use or model modification. Such restrictions would narrow the appeal for enterprises seeking long-term infrastructure investments, regardless of the model’s technical performance.
Advertisement
Moonshot AI’s recent Kimi K3 release illustrates why this distinction matters. While Kimi K3 made its weights openly available to all, its licensing terms included specific terms including a disclosure and a commercial license requirement for those offering it as a “Model as a Service.”
Until Alibaba publishes Qwen3.8-Max’s license, organizations considering self-hosting should treat the open-weight announcement as promising but incomplete.
An increasingly crowded frontier
Qwen3.8-Max arrives during one of the fastest-moving periods in the history of foundation models.
Within weeks, developers have seen major releases from Moonshot AI, OpenAI, Anthropic and others, each emphasizing different strengths: reasoning, coding, multimodality, autonomous agents or economics.
Advertisement
Alibaba’s contribution is notable because it combines competitive benchmark performance, aggressive pricing, a million-token context window and a stated commitment to releasing weights for its flagship model.
Whether it becomes the preferred platform for enterprise autonomous agents will ultimately depend less on leaderboard positions than on broader independent validation, production reliability and the licensing terms accompanying the forthcoming weight release.
Those factors—not benchmark charts alone—will determine whether Qwen3.8-Max becomes a genuine alternative to the leading American proprietary models or simply another impressive entrant in an increasingly crowded frontier AI race.
The Senate Commerce Committee is set to consider S. 737, the SCREEN Act, a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech.
Unlike many state-age verification laws—which have been harmful in their own right—the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.
The SCREEN Act does not merely require users to attest they are adults. It specifically states that “requiring a user to confirm that the user is not a minor shall not be sufficient.” In practice, that means platforms would have to verify users’ ages using methods tied to their real identities. Providing proof of age online is dramatically different, and far more invasive, than showing your ID at the door to a bartender or bouncer. In the physical world, the bouncer at the door looks at your ID card, confirms you’re old enough, and gives it back to you. Under the SCREEN Act, the “bouncer” will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time.
The consequences of the bill won’t be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults.
Advertisement
Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people’s private information.
In other words, the third parties tasked with verifying a user’s age on a platform could sweep up a lot of personal info they don’t actually need and then could use that information for any number of purposes, so long as they deem their actions reasonable. Companies would then be allowed to keep the information users have been compelled to turn over for as long as possible, raising security and privacy issues along the way.
The SCREEN Act Attacks Your Right To Use VPNs
The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users’ ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking.
VPNs mask your real location by routing your internet traffic through a server somewhere else. When you visit a website through a VPN, that website only sees the VPN server’s IP address, not your actual location. It’s like sending a letter through a P.O. box so the recipient doesn’t know where you really live. VPNs are a privacy and security tool used by millions of internet users every day, and their use should not be treated as suspect. It is particularly galling that the SCREEN Act forces users who intentionally take steps to protect their privacy to identify themselves.
Advertisement
The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users.
We may receive a commission on purchases made from links.
You only have so much room to pack for your camping trip, but setting a small amount of space aside for these handy mini gadgets can be worth it to keep you safe and informed. Whether you’re into roughing it in tents and sleeping bags or glamping in a cozy camper, these mini gadgets are worth considering for the safety and convenience they provide in such compact packages.
Starting with the Midland E+Ready Compact Emergency Crank Radio, this 0.65-pound radio keeps you up to date with the latest weather developments so you can stay ahead of rain, sleet, snow, and more. That alone is a vitally important function, but it also comes equipped with a number of other quality of life features, including an LED flashlight and emergency SOS beacon. Similarly, the Garmin inReach Mini 2 is a tiny satellite communication that gives you the peace of mind of knowing you’re never away from a reliable source of communication.
Advertisement
And if you’re prone to losing things and leaving them behind – or you worry about it often – look into Apple AirTags (2nd gen), which are coin-sized Bluetooth trackers that you can slip into a wallet, attach to a set of keys, or toss into a backpack for easy tracking from your phone.
Advertisement
Midland E+Ready Compact Emergency Crank Radio
Staying up to date with current weather developments is important because you never know when you may need to prepare for rain or seek shelter from severe weather. It’s not always feasible to stay informed when you’re away from electricity and an internet connection, though, which is why emergency radios like the Midland E+Ready Compact Emergency Crank Radio exist.
You can power Midland’s emergency radio using three different methods: solar, crank, and rechargeable battery. So even if there’s no outlet or Wi-Fi router in a 50-mile radius, you still have access to AM/FM radio and NOAA weather alerts while you camp. Weather alerts are the Midland E+Ready Compact Emergency Crank Radio’s main function, but they’re not the only one. It also comes equipped with a 1,400 Lux brightness LED flashlight, which doubles as an emergency SOS beacon if you’re ever stranded and need to be easily located.
Plus, at just 0.65lbs and 2.20 x 7.70 x 5.60in, it’s tiny and featherweight, making it the perfect accessory for car camping or slipping into a backpack for peace of mind. At $59.99 when you shop at Walmart, the Midland E+Ready radio offers peace of mind for well under $100.
Advertisement
Apple – AirTag (2nd generation)
The Apple AirTag is a pretty ingenious little product that helps you keep tabs on anything and everything important. At its core, it’s a Bluetooth tracker that syncs up to your phone. When you’re taking valuables or keepsakes with you on your next trip, consider slipping one of these into the bag or attaching it with a keychain so you’ll always know where it is. You can pop one of these into a rucksack or wallet, add it to your key ring, or simply keep it on your person so that other people are able to locate you through Apple’s Find My. You can also turn on separation alerts so the tag will notify you if you accidentally leave it (and its attached item) behind.
Apple’s trackers weigh just 11.8g and measure in at only 1.26 x 0.31in, so you’ll barely even know they’re there. They’re also IP67 water and dust resistant, which is important for hiking, biking, and water activities like fishing and kayaking. As for the tracking itself, you can locate the lost item in the Find My app, and you can also play a sound from the AirTag’s built-in speaker (like AirPods). Apple’s 2nd-gen AirTags are $29 at Amazon, but regularly go on sale (including a discounted price of $27 at the time of writing).
Advertisement
Garmin inReach Mini 2
The Garmin inReach Mini 2 also landed a spot on our roundup of the 4 most useful camping gadgets you can buy, and for great reason. It helps you keep in touch even when you’re in the middle of nowhere – so if you like adventures and remote excursions, this tiny but robust satellite communicator is definitely worth a thought. At just 2.04 x 3.90 x 1.03in and weighing in at 100g, the inReach Mini 2 can fit comfortably in the palm of your hand or a small pocket of your backpack.
Advertisement
Garmin’s inReach Mini 2 enables two-way messaging via satellite communication, offers a quick way to send SOS alerts to Garmin Response (a 24/7 emergency contact service), and provides live tracking for friends and family to follow your journey. Despite its small stature, though, the inReach Mini 2 features a durable design that will have no problems accompanying you on your camping trips, complete with IPX7 water resistance for puddles, rain, and snow.
Aside from its primary communication function, the inReach Mini 2 also has a few nice quality of life features out of the box, including weather forecasts and updates through the inReach Weather Forecast Service, a digital compass for navigation, and trip planning and route storage. The inReach Mini 2 runs for $399.99 at Amazon, though it’s marked down to $349.99 at the time of writing.
Advertisement
How we selected these mini camping gadgets
Miljan Zivkovic/Shutterstock
We chose these mini camping gadgets based on a number of key factors, including price, design, availability, feature set, and portability. We analyzed expert and user reviews, placing particular emphasis on how well these products actually performed in real-world settings, as well as relevant roundups like the most useful camping gadgets you can buy and useful camping gadgets that you can use year-round to compare similar gadgets. As this is a list of mini camping gadgets, we set a weight limit of one pound.
We then narrowed the picks for this list down based on how well the products perform in each of the key categories mentioned, as well as which are most applicable to the majority of campers. In other words, do we believe the product is genuinely worth recommending to most people in the market for new camping gear? If so, we listed it here.
Not long ago, I wrote a news brief announcing the Sony 1000X THE COLLEXION limited-edition headphones after attending a product briefing with Sony’s engineers. What stood out was not simply the promise of another premium wireless headphone, but the company’s determination to establish a new luxury standard for the 1000X series.
THE COLLEXION was designed to bring together everything Sony had learned during the first decade of the 1000X lineup and package it in something more distinctive, refined, and boutique. That was an ambitious goal, because Sony’s 1000X headphones have earned a permanent place on our best-of lists largely through excellent noise cancellation, strong sound quality, useful features, and outstanding battery life—not because anyone confused them with luxury goods.
Some of the earlier models looked better to my eye, but the series has generally favored practical polymer construction over visual drama. A few models have also raised durability concerns along the way, with designs that felt more plastic than premium.
Sony already knew how to build an excellent noise-cancelling headphone. The real question was whether it could finally build one that looked and felt every bit as expensive as the technology inside it.
Advertisement
There was just one problem: based on what I had seen up to that point, I didn’t think they looked all that good.
Sony 1000X THE COLLEXION wireless headphones are available in white or black.
I had reviewed the press materials, and the Sony engineer I spoke with wore a pair of THE COLLEXION headphones during our briefing. In white, they looked a bit like the love child of the Sonos Ace or, dare I say it, the Apple AirPods Max and Sony’s own WH-1000XM5. They were clean and understated, but also rather nondescript for a flagship model and perhaps a little underwhelming for something positioned as a luxury product.
That could become a serious problem for Sony. The engineer had already acknowledged that the less expensive WH-1000XM6 offered slightly better active noise cancellation, which has historically been one of the biggest reasons consumers buy Sony’s 1000X headphones. If THE COLLEXION could not win on performance, it needed to make a convincing case through its materials, craftsmanship, comfort, and design.
I thanked Sony for the opportunity to audition the new model and quietly hoped my first impression was wrong. Otherwise, the review I was about to write was going to be considerably less comfortable than the headphones.
Advertisement
Related Reviews:
Sony Finally Looks the Part
Once I had THE COLLEXION in hand, most of those concerns disappeared. The headphones look and feel considerably more luxurious than my initial viewing had suggested.
The headband features a brushed stainless steel outer band with a memory foam underside covered in leather. The adjustment arms use a distinctive tuning fork design, with one arm concealed inside the headband and another extending along the outside.
Sony has paid close attention to the finishing here. The underside of the outer arm is polished to a mirror finish, while its face is bead blasted to match the brushed surface of the headband. The Sony name appears near the top of the matte section, although the light has to strike it at the right angle before the branding becomes visible.
Advertisement. Scroll to continue reading.
The lower section of the fork, which connects the headband to the ear cups, is also made from polished steel. Its chrome like appearance adds some visual drama without turning THE COLLEXION into something gaudy. In person, the combination of brushed metal, polished steel, leather, and restrained branding feels far more convincing than it did in Sony’s press images.
The ear cups and pads use the same leather found on the underside of the headband, while the buttons, USB port, and 3.5mm connection repeat the brushed metal finish used elsewhere. That consistency gives the design a more cohesive and deliberate appearance.
Advertisement
The buttons are not simply painted to resemble metal. They are made from brushed aluminum, as are the surrounds around both ports. Beyond looking better, those metal surrounds should provide additional reinforcement and improve durability over time.
Perhaps the most noticeable physical change is the shape of the ear cups. They are slightly smaller on the outside than those on the WH-1000XM6, but the pads have a larger internal opening and greater depth. That makes THE COLLEXION more comfortable for those of us whose ears were not designed with compact Japanese industrial design in mind.
Placed side by side, THE COLLEXION’s ear cups are approximately 3mm thinner and slightly narrower than those of the XM6, while their overall height remains nearly identical. The changes are subtle, but the additional space inside the pads makes a meaningful difference during longer listening sessions.
The only missed opportunity is the pad attachment system. Sony continues to use plastic tabs rather than magnetic mounts. Magnetic pads would have made replacement easier, elevated the overall experience, and helped distinguish THE COLLEXION further from the XM platform beneath it.
Advertisement
The case is another clear step up from previous Sony models, with a carry handle integrated into the body and magnetic closures that feel more appropriate for a premium product.
Sony understands that a luxury item should not arrive in the equivalent of a plain brown wrapper. The company has done a good job of turning what could have been a basic transport and storage container into an integral part of the overall package. It feels more substantial and thoughtfully designed than the cases supplied with the Apple AirPods Max and Sonos Ace.
The case is also slightly smaller than those included with previous 1000X models, which is a welcome improvement. Travelers are often forced to choose between protecting an expensive pair of headphones and reclaiming valuable space in a carry on bag.
THE COLLEXION largely eliminates that dilemma. The case is compact and well designed enough that bringing it along feels like the obvious choice rather than an inconvenience.
Advertisement
Sony Prioritizes Sound Over ANC
Sony has battled Bose for active noise cancellation supremacy for years, but THE COLLEXION takes a distinctly different approach.
Sony is unusually candid about that distinction. If you want the company’s best ANC performance, buy the WH-1000XM6. THE COLLEXION is aimed instead at becoming the best sounding wireless headphone in its price class.
Advertisement. Scroll to continue reading.
Reaching that goal required far more than dressing up an existing 1000X model in leather and polished steel. Sony reworked nearly every part of the internal design, including thicker copper traces and lower internal impedance to improve signal integrity.
Advertisement
The new driver diaphragm uses linearly aligned carbon fibers to reduce weight and improve speed, while Sony’s V3 processor appears in a headphone for the first time. That additional processing power allows for the most advanced digital signal processing Sony has yet offered in one of its headphones.
THE COLLEXION may share its family name with the rest of the 1000X series, but internally it represents a much more ambitious rethink of what a Sony wireless headphone can be.
The 30mm drivers have a nominal impedance of 48 ohms and a stated frequency response of 4 Hz to 40 kHz when used with a wired connection. That range narrows to 20 Hz to 20 kHz over Bluetooth.
I listened both wired and wirelessly using LDAC and LC3. The wired connection produced noticeably more sub bass, suggesting that low frequency extension is limited somewhat by the codec being used during wireless playback.
Advertisement
One important detail is that THE COLLEXION must remain powered on even when connected by cable. As a result, the source device is not driving the 48 ohm transducer directly in the way it would with a conventional passive headphone. The internal amplification and signal processing remain part of the chain.
Bluetooth 6.0 is supported, along with SBC, AAC, LDAC, and LC3. That provides broad compatibility with current source devices and some protection against the next wave of wireless audio changes. Multipoint connectivity is also included, making it easy to remain connected to a phone and a laptop or digital audio player at the same time.
Noise cancellation may not be the primary focus, but Sony has hardly ignored it. THE COLLEXION uses a 12 microphone system combined with both the new V3 processor and Sony’s QN3 noise cancelling processor. It draws heavily from the company’s previous 1000X models, even if Sony is no longer claiming that ANC is the main reason to buy it.
The Battery Life Claim Holds Up
With wired and wireless operation, active noise cancellation, and several DSP effects available, battery life can vary considerably depending on how THE COLLEXION is configured.
Advertisement
With every feature enabled and the volume higher than it probably needed to be, I still managed more than 22 hours of playback. With a more realistic combination of listening levels and features, battery life exceeded 32 hours, which closely supports Sony’s claim.
Quick charging is also included, as it should be at this price. A five minute charge provides roughly 90 minutes of playback, while a full recharge from 20 percent to 100 percent took approximately two hours according to the Sony app.
Battery life is not the headline feature here, but THE COLLEXION lasts long enough that most users will spend far more time listening than looking for a charging cable.
Advertisement. Scroll to continue reading.
Advertisement
Putting Sony’s V3 Processor and AI to Work
The new V3 processor was mentioned in the hardware section, but its benefits become much more obvious once you open the Sony app and explore the settings.
DSEE Extreme is one of the clearest examples. For those unfamiliar with it, DSEE stands for Digital Sound Enhancement Engine. In its original form, it was essentially Sony’s implementation of upsampling. Nothing more, nothing less.
The Extreme version adds artificial intelligence to the process. Yes, AI is the buzzword of the moment, and no, the headphones are not listening to your conversations or tracking your movements.
What the processor is doing is analyzing the music and determining how best to create the additional samples required during upsampling. The extra processing power allows Sony to use more sophisticated algorithms, reduce artifacts, and improve clarity with compressed or lower resolution recordings.
Advertisement
The results vary depending on the track, but DSEE Extreme can produce a meaningful improvement with some material. Sony’s claim that it restores lost detail is a little generous, since information removed during compression cannot simply be recovered. What it can do is make a more intelligent estimate of what is missing and rebuild the signal in a cleaner and more convincing way.
In addition to improving upsampling, the extra processing power gives Sony considerably more flexibility with sound tuning.
The app includes six preset EQ profiles, along with a 10 band equalizer that allows listeners to shape the sound to their liking. Two custom profiles can be saved for later use, making it easy to create separate settings for different genres, sources, or listening environments.
Sony also includes five distinct Listening Modes. Standard and Background provide two channel presentations, while Music, Cinema, and Game use spatial processing to create a more immersive three dimensional soundstage. Each mode emphasizes a different range of frequencies and spatial cues based on what listeners are likely to expect from that type of content.
The adaptive listening controls are even more useful. THE COLLEXION can automatically change settings based on your location or activity. Arrive at the gym, for example, and the headphones can switch to a saved Custom 2 profile with more bass to help keep the workout moving.
Advertisement
Sit down in the office, and they can automatically engage Background mode once they recognize that you are stationary and working. It is the kind of automation that could easily feel like a gimmick, but once configured properly, it removes the need to keep opening the app every time your surroundings change.
The app is well organized, with quick access to the features most listeners will use regularly. A single comprehensive menu also provides direct access to every available setting.
There is a lot to explore, and the number of options can feel slightly overwhelming at first. Most of them are intuitive and genuinely useful, however, so it is worth spending some time learning how the app works and configuring THE COLLEXION to suit your habits.
Advertisement. Scroll to continue reading.
Advertisement
The touch controls on the ear cups are also better than most. They respond to taps and swipes with minimal delay, allowing users to play or pause music, skip tracks, and adjust the volume with simple gestures.
That means routine commands can be handled directly from the headphones rather than forcing you to reach for your phone and rummage through the app every few minutes.
Listening
Sony’s representatives made it clear that THE COLLEXION would sound different from a typical 1000X model, and that departure is obvious from the first listen. The presentation is warmer, fuller, and occasionally a little dark.
Bass is mildly elevated, with most of the emphasis concentrated in the sub bass before the response moves closer to neutral around 150 Hz. That character is present with both wired and wireless connections, although the wired connection delivers greater depth and extension at the bottom.
Advertisement
Bass has good weight, impact, and fullness without becoming excessive in the way it can with some competitors, including the AirPods Max. It adds authority without overwhelming the rest of the mix.
The mid bass is also tighter than it is on the WH-1000XM6, and the transition into the lower midrange is cleaner. That improves clarity and prevents bass notes from bleeding into vocals and instruments.
I hope this part of the tuning carries forward into future generations of the 1000X series. It is a meaningful improvement and one of the clearest signs that Sony was aiming for more than a dressed up XM6.
The midrange is where THE COLLEXION takes its biggest step forward over previous 1000X models. Timbre is more convincing, instruments sound more natural, and there is noticeably more energy through the middle of the frequency range.
Advertisement
These headphones are equally comfortable with growling guitars and snarling vocals or jazz recordings built around trombone and saxophone. Strings have life and texture, while piano sounds realistic across most of its range, even if the upper registers could use slightly more energy.
That softer presentation appears intentional. Sony keeps the upper midrange and lower treble firmly under control, and THE COLLEXION consistently favors smoothness over aggression. Even recordings with obvious sibilance struggle to become unpleasant through these headphones.
There is a slight dip around 1 kHz that helps create a broader sense of space, although it can occasionally make lower vocals sound a little more distant than they should.
Treble is smooth and laid back, with almost no tendency toward fatigue. That makes THE COLLEXION an excellent choice for long listening sessions, although the tradeoff is a modest reduction in air and sparkle at the top.
Advertisement
Advertisement. Scroll to continue reading.
I generally prefer a little more brightness, but Sony has done a good job of preserving enough detail and energy to prevent the presentation from feeling closed in. The information is still there, although listeners may occasionally have to work a little harder to hear it.
The soundstage is moderately sized, but better proportioned than that of any previous 1000X model. Both width and depth are more expansive than they are on the WH-1000XM6, at least to my ears.
Imaging is also quite good. Sounds moving across the stage are easy to follow, and individual effects can be placed with convincing precision.
Advertisement
THE COLLEXION is not marketed as a gaming headphone, but its spatial presentation makes it a strong option for listeners who want one headphone capable of handling music, movies, and gaming without feeling compromised in any of those roles.
Sony 1000X THE COLLEXION – Rear of left earcup
ANC: Less Aggressive, More Transparent
Active noise cancellation is always a balancing act, and Sony is quick to point out that THE COLLEXION strikes a different balance than the WH-1000XM6. Listeners who want the absolute maximum level of noise removal will still be better served by the XM6.
THE COLLEXION instead takes a more careful approach: remove as much outside noise as possible without compromising the music. Sony succeeds surprisingly well. Switching ANC on and off in the middle of a track produces far less change in tonal balance and overall presentation than many experienced ANC users will expect.
Low, steady noises are removed with ease, as expected. Higher pitched sounds and sudden bursts are less effectively suppressed, but they are still reduced enough to become considerably less intrusive.
THE COLLEXION may trail the XM6 slightly in absolute noise cancellation, but the difference is smaller than Sony’s own messaging might suggest. Some of that gap may also come from the ear cups providing slightly less passive isolation in exchange for significantly better comfort, at least for me.
Advertisement
In practice, ANC performance is remarkably close to both the Bose QuietComfort Ultra and Sony WH-1000XM6. THE COLLEXION may not win the contest for complete silence, but it does a better job of preserving the sound quality that made you put the headphones on in the first place.
Sony 1000X THE COLLEXION Specifications
Model: WH-1000XX / 1000X THE COLLEXION
Driver: 30mm carbon fiber diaphragm
Frequency Response: 4 Hz – 40 kHz wired; 20 Hz – 20 kHz via Bluetooth
Nominal Impedance: 48 ohms
Bluetooth: Version 6.0
Codecs: SBC, AAC, LDAC, and LC3
Processors: Sony V3 and QN3
Microphones: 12 microphone ANC system
Battery Life: Up to approximately 32 hours, depending on settings
Quick Charging: 5 minutes for approximately 90 minutes of playback
Sony often takes a beating for being the GM of the audio world. It produces a vast number of consumer products for the mass market, many of them aimed squarely at buyers looking for value rather than exclusivity.
THE COLLEXION is a reminder that Sony can still build a world beater when it decides to. Much like the Corvette ZR1X, it delivers much of the performance, engineering, and refinement associated with boutique competitors without requiring an Italian exotic price tag.
What makes THE COLLEXION unique is not class leading noise cancellation. Sony already sells the WH-1000XM6 for listeners who care most about removing every last trace of outside noise. Instead, this model combines the best sound Sony has produced from a 1000X headphone with improved comfort, stronger materials, better midrange timbre, tighter bass, and a level of design refinement that previous models never quite achieved.
Advertisement. Scroll to continue reading.
Advertisement
It is not perfect. The treble may be too relaxed for listeners who prefer more sparkle and air, the ear pads still rely on plastic attachment tabs rather than magnetic mounts, and the headphones must remain powered on during wired use. ANC is excellent, but it is not the absolute best Sony offers.
At $649, THE COLLEXION (model WH-1000XX) represents a substantial leap over the WH-1000XM6. It is aimed at listeners who want Sony’s most comfortable and best sounding wireless headphone and are willing to pay more for improved materials and a more luxurious ownership experience.
For those buyers, it is a leap worth taking.
Pros:
Sony’s best sounding 1000X headphone to date
Warm, natural midrange with tighter, better controlled bass
Premium materials and noticeably improved build quality
Excellent comfort with deeper, more spacious ear pads
Strong battery life and extensive app customization
Cons:
Treble may be too relaxed for listeners who prefer more sparkle
ANC falls slightly short of the WH-1000XM6
Must be powered on for wired listening
Ear pads still use plastic tabs rather than magnetic attachments
Norton was always a PC company — Norton Commander, the file manager that launched a thousand clones, was only ever available for DOS, like the rest of the company’s offerings in those days. If they’d decided to port it to the C64, though, it would likely look a lot like [retro3872809] aka [Chicken 64]’s Multi Floppy Commander with Turbo, available on GitLab.
As you might be able to see on the screen shot above or in the demo video below, the application provides an 80-column interface with a split view to show a pair of floppies side-by-side. Not that you’re limited to two floppies, however. The software is happy to swap between all the drives on the bus, to the C64’s maximum of four. All four drives will be usable since the file manager lives on a cartridge.
All drive models are supported, though not all have turbo. As a file manager, it looks like it has the normal functionality you’d expect: renaming, copying, moving and deleting files and directories. You can also launch programs or print disk listings, assuming you have a printer attached to your Commodore.
A new NYT Strands puzzle appears at midnight each day for your time zone – which means that some people are always playing ‘today’s game’ while others are playing ‘yesterday’s’. If you’re looking for Monday’s puzzle instead then click here: NYT Strands hints and answers for Monday, August 3 (game #883).
Strands is the NYT’s latest word game after the likes of Wordle, Spelling Bee and Connections – and it’s great fun. It can be difficult, though, so read on for my Strands hints.
Want more word-based fun? Then check out my NYT Connections today and Quordle today pages for hints and answers for those games, and Marc’s Wordle today page for the original viral word game.
Advertisement
SPOILER WARNING: Information about NYT Strands today is below, so don’t read on if you don’t want to know the answers.
Latest Videos FromTechRadar
Advertisement
NYT Strands today (game #884) – hint #1 – today’s theme
What is the theme of today’s NYT Strands?
• Today’s NYT Strands theme is… Staying healthy
NYT Strands today (game #884) – hint #2 – clue words
Play any of these words to unlock the in-game hints system.
THIN
LINE
ZINC
CORE
FORMAT
CRAM
FILLER
NYT Strands today (game #884) – hint #3 – spangram letters
How many letters are in today’s spangram?
• Spangram has 8 letters
Advertisement
NYT Strands today (game #884) – hint #4 – spangram position
What are two sides of the board that today’s spangram touches?
• First side: top, 3rd column
• Last side: bottom, 4th column
Right, the answers are below, so DO NOT SCROLL ANY FURTHER IF YOU DON’T WANT TO SEE THEM.
Advertisement
Advertisement
NYT Strands today (game #884) – the answers
(Image credit: New York Times)
The answers to today’s Strands, game #884, are…
REFILL
CONSULT
IMMUNIZATION
MEDICINE
COUNTER
SPANGRAM: PHARMACY
My rating: Hard
My score: 2 hints
Struggling to find anything but non-game words, I took a hint and was given REFILL — a word that, rather than help me understand the theme of “staying healthy”, confused me.
Sign up for breaking news, reviews, opinion, top tech deals, and more.
Looking for clarity, I took another hint with CONSULT — and that just sent me deeper into bafflement.
Taking a completely different approach I focused on the letter Z and was able to unfurl IMMUNIZATION, which finally got me to today’s medical theme and the spangram of PHARMACY.
Advertisement
Yesterday’s NYT Strands answers (Monday, August 3, game #883)
ONLY
UNIQUE
SPECIAL
EXCLUSIVE
SINGULAR
SOLE
SPANGRAM: ONEOFAKIND
What is NYT Strands?
Strands is the NYT’s not-so-new-any-more word game, following Wordle and Connections. It’s now a fully fledged member of the NYT’s games stable that has been running for a year and which can be played on the NYT Games site on desktop or mobile.
I’ve got a full guide to how to play NYT Strands, complete with tips for solving it, so check that out if you’re struggling to beat it each day.
Last week we wrote about how Elon Musk’s xAI had filed a lawsuit to attempt to block Minnesota’s anti-nudify app law. As we tried to explain, even if you (reasonably, understandably) dislike both Elon and “nudify” apps, there were real problems with the Minnesota law. In particular, it was not narrowly tailored to just target truly harmful image edits. Indeed, it wasn’t even limited to the non-consensual use of the tech. The state’s Supreme Court had already handed the Minnesota legislature a clear roadmap for drafting a law like this that would pass strict scrutiny. The legislature ignored it.
However, the lawsuit was filed just days before the law was set to go into effect, which was called out by Minnesota’s Attorney General in arguing against a temporary restraining order:
First, X.AI’s lack of diligence confirms that a TRO is unnecessary. The company waited until the last minute to sue…
And that seemed to influence Judge Donovan Frank, who denied the motion for the TRO mainly because Elon waited until the last minute to file.
The Court respectfully denies the request for a temporary restraining order before tomorrow. xAI filed the motion on July 29, 2026, nearly three months after the law was signed, and only three days before the law is set to take effect. Such a delay in bringing the action and the motion suggests that harm is not immediate.
And, sure, it was kind of silly for Musk to wait right up until the law was set to go into effect, but that’s not all that rare with challenges to these kinds of laws. I also find the court’s suggestion that the harm isn’t immediate a bit odd, given that (as xAI had rightly pointed out) the potential liability under this law is massive: $500,000 per “access, download, or use.” That means any single use of Grok to edit an image that violates this law (which, as we discussed, goes way beyond nonconsensual sexual imagery, and could even cover someone editing a photo of themselves in a way they endorse) could lead to a huge bill for the company. And it’s now in effect, meaning in theory Minnesota’s AG, Keith Ellison, could already seek fines against the company — though there’s no indication that his office has done so yet. And while it may be politically appealing to try to enforce immediately, that may play badly before the court when there are hearings coming up in a few weeks on a preliminary injunction.
Advertisement
It’s also unclear if xAI actually changed anything on its end. In its filing, the company said that if the law went into effect, it would need to restrict access to certain features:
Confronted with $500,000-per-image strict liability and no safe harbor, xAI has no practical choice but to restrict Grok Imagine’s image-editing features in various ways when the statute takes effect on August 1, 2026
But the law has gone into effect, and as far as I can tell, there’s been no announcement of any changes. It’s possible such changes have been made already and just not announced. But it does come off as a bit weak to file a lawsuit on Monday saying that “if this law isn’t fixed by Saturday we’ll make big changes” and then have the law go into effect… and those changes are not publicly announced anywhere.
This ruling may not mean very much at all. The court has ordered both sides to brief a preliminary injunction over the next couple weeks, with a hearing on August 19th that can get into the actual First Amendment problems with the law. That also means xAI will likely have to explain, in those filings, whatever restrictions it has or hasn’t added to its systems.
xAI’s initial filing was not bad, but I hope they lean more heavily on the case I discussed in my last post, in which Minnesota’s Supreme Court spelled out exactly what the state’s non-consensual intimate imagery law needed to survive strict scrutiny. Because that case walks through, in great detail, the steps a (somewhat similar) law had to take to pass strict scrutiny and survive the First Amendment — even as the court acknowledged the law was punishing a form of protected speech.
Advertisement
There remain some oddities around this law, starting with the fact that the ACLU of Minnesota backed it in the first place — a surprising stance for the ACLU — before reversing course once Musk sued:
xAI’s criticism of the law is drawing support from some free-speech advocates including the American Civil Liberties Union of Minnesota, which supported passage of the law in an earlier form in February but has since turned against it.
“While we believe that creating the technology to alter or ‘nudify’ photos of identifiable people is protected by the First Amendment, we also recognize that the non-consensual creation and dissemination of such material can inflict damage on people appearing in those images,” the ACLU of Minnesota said in a statement Friday.
“In engaging with lawmakers on this issue, we hoped to strike an appropriate balance between First Amendment rights and the ability of people harmed to seek remedial measures, not unlike the remedies available to people harmed by defamation. The final version of the bill does not strike that balance,” the organization said.
Seems like the sort of thing you should have worked out before supporting the law, but fine.
Advertisement
Also, I had mentioned in my last article that some believe the law was written so badly on purpose, to convince Musk to sue in order for Democrats to use it as a political tool and… they are certainly making political hay of it on X, where they seem to be overjoyed that they can mock Elon.
And, sure, mocking Elon is fun. But if you’re going to mock him, it should be over the things he’s actually doing that are problematic.
The issue with this law isn’t that it’s trying to deal with the issue of nudify apps. Or that it’s trying to stop Elon from doing terrible things. It’s that it did so in such a ham-fisted, damaging, obviously unconstitutional manner that bans way more than it claims, is not narrowly targeted, and pretty clearly cannot survive strict scrutiny. Minnesota had the roadmap to pass a legitimate version of this law. It chose not to do so. That Musk didn’t receive the immediate TRO due to the late filing doesn’t make the law a good law. The proper thing for Minnesota’s legislature to do would be to write a law that actually abides by the First Amendment, but perhaps that wouldn’t get them the kinds of headlines they’re getting now.
ISA Matters: Valve developers have been working hard to finalize the software stack for the upcoming Steam Frame. Despite using an Arm-based processor, the VR headset is expected to support both PC and Android games thanks to a complex compatibility layer.
Valve recently updated the Steam pages for Lepton and FEX, two tools designed to improve compatibility between the popular PC gaming platform and Arm-based devices. The tools are expected to play a major role in turning the upcoming Steam Frame into a “real” gaming headset from the get-go.
Lepton and FEX still lack public store pages on Steam, but their update histories can be viewed through SteamDB’s archive. The first hints about Lepton appeared online in 2025, suggesting that Valve was embarking on yet another major compatibility project. Just as Proton acts as a compatibility layer for Windows games on Linux using Wine, Lepton is expected to leverage the container-based Waydroid system to run Android apps on a full Linux distribution.
Meanwhile, FEX is an emulator designed to translate API calls and recompile code from x86 applications into native implementations for the Arm64 instruction set architecture (ISA). The emulator is designed to reduce emulation overhead and improve performance, and it can already offer “broad” compatibility with both 32-bit and 64-bit x86 binary applications – i.e., games.
Advertisement
FEX was previously advertised as a compatibility tool that could be used alongside Wine/Proton to play Windows games on Arm devices. With Valve taking part in the project, the emulator could quickly gain traction, just as Proton has become a major player and software product in the Linux gaming market.
Lepton, Proton, and FEX are expected to handle game compatibility within the Steam Frame ecosystem. The upcoming VR headset is based on a Snapdragon 8 Gen 3 Arm64 SoC and a SteamOS build based on the Arch Linux distribution. Valve is also known for providing financial support to the Arch project.
Steam Frame’s compatibility setup should work something like this: Lepton will handle Android games in its container-based system, while FEX will translate x86-64 native code to Arm. Finally, Proton will run Windows-based software on the Arm architecture.
Earlier this year, Valve announced that the headset’s final release date had been delayed due to the memory shortage crisis caused by AI data center overprovisioning. Now that two major pieces of the device’s software stack are finally showing their “faces” in public, the actual launch date for Steam Frame should not be too far away.
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
SOCRadar’s Threat Research Unit says DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.
The service handles much of the infrastructure required to conduct the attacks, including hosting the steganographic PNG images, managing session and signal endpoints, providing encryption keys, and automatically rebuilding payloads.
DOUBLECUP customers are responsible for creating and hosting the websites used to display the ClickFix prompts, adding the generated frontend code, and implementing any additional obfuscation or anti-analysis measures.
SOCRadar discovered DOUBLECUP while investigating an open directory at 213[.]139.77[.]109:9090 that contained test files. The same IP address was later identified as hosting the service’s licensing panel.
Advertisement
To launch an attack, a DOUBLECUP customer uses the Go-based Windows application to configure the campaign’s domain, URL path, steganography method, embed type, execution action, and payload locations.
This generates an API configuration endpoint that returns the steganographic image URL and file size, session endpoint, and commands customized for Chrome, Edge, Firefox, Brave, and Opera.
Operators then add DOUBLECUP’s code to their ClickFix sites, which retrieves the configuration, preloads the steganographic image into the victim’s browser cache, registers the session, selects the command matching the victim’s browser, and copies it to the clipboard when the page is opened.
Malware hidden in the browser cache
In a new report, SOCRadar says it observed DOUBLECUP ClickFix campaigns using fake CAPTCHA prompts on login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce, with the malicious code loaded through embedded iframes.
Advertisement
When a victim visits one of these sites, DOUBLECUP registers the session, determines the victim’s public IP address, and forces the browser to download and cache a malicious PNG image.
The page then displays fake CAPTCHA-style instructions that attempt to convince visitors to paste and run a command automatically copied to their clipboard.
DOUBLECUP attack flow
Once executed, the command searches the browser cache for the PNG based on its exact file size and uses the findstr or certutil commands to recover and execute the hidden first-stage payload inside the image.
The first payload launches a fileless second-stage dropper, which retrieves the victim’s public IPv4 address and uses it to create a decryption key for the final encrypted payload.
After verifying the decrypted payload against a hardcoded SHA-256 hash, the dropper executes it in memory. SOCRadar says the final payloads are CountLoader and a new DeviceManager RAT.
Advertisement
2 malware payloads
SOCRadar identified two malware families delivered through DOUBLECUP, which are an updated version of CountLoader that targets Windows and macOS and what is believed to be a previously undocumented DeviceManager RAT.
CountLoader is used to harvest information about infected systems, checks for cryptocurrency wallet applications and browser extensions, determines whether Signal Desktop is installed, and establishes persistence through scheduled tasks.
CountLoader can also download and execute files, including MSI packages, PowerShell modules, and DLLs.
SOCRadar also recovered a macOS version compiled for Intel and Apple Silicon devices, which installs a LaunchAgent for persistence and uses built-in utilities such as curl, sw_vers, system_profiler, and ioreg to communicate with attacker-controlled servers.
Advertisement
DOUBLECUP was also seen delivering the DeviceManager malware, a modular Python-based Windows RAT that uses blockchain smart contracts to determine the IP address of its command-and-control server.
In countries not part of the Commonwealth of Independent States (CIS), DeviceManager collects the machine GUID, disk identifier, user SID, hostname, username, operating system version, architecture, installed antivirus software, and domain information.
The malware uses a technique known as EtherHiding to retrieve its current C2 address from an Ethereum or Polygon smart contract, which makes it more resistant to disruption attempts.
The RAT uses DNS A and TXT records to steal system information, retrieve commands to execute, download payloads, and send command output back to the attackers.
Advertisement
This is not the first time ClickFix attacks have used steganography, as Huntress previously documented campaigns that concealed LummaC2 and Rhadamanthys payloads within the pixel data of PNG images.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
You must be logged in to post a comment Login