"A CAPTCHA should not ask users to run code," Microsoft added.
How the ClickFix campaign hid a VBScript payload in the browser cache
Microsoft Threat Intelligence described on October 3 a ClickFix social-engineering campaign that pre-fetched a VBScript payload into the victim's browser cache and disguised it as an image so the malicious script was already present on disk before the victim ever ran a command. A cluster of compromised websites led visitors into the attack flow, according to Microsoft's post on X.
Rather than delivering the payload after the user acted, the sites loaded the script into the browser cache ahead of time. That prefetching let the attackers obscure the file and avoid limitations imposed by the Windows Run dialog: the pasted command only had to locate and execute a file already stored on the device.
The Run dialog trick: cmd.exe, file-size matching, and a simple paste
The social-engineering stage presented a fake CAPTCHA pop-up instructing users to open Run, paste from their clipboard and press Enter. The pasted command launched cmd.exe, which then searched the browser profile folder for cached files whose names began with "f_". Instead of looking for a content marker, the attack compared each candidate file's size to an expected value.
When a size match occurred, the command copied the cached file to a temporary folder, renamed it with a .vbs extension, and executed it with wscript.exe. This size-based matching, combined with prefetching, let the attackers both conceal the payload and bypass character-length constraints on what could be pasted into the Run box.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePost-execution behavior: WMI, PowerShell, and in-memory injection
After the VBScript ran, it used Windows Management Instrumentation (WMI) to collect host details, then downloaded a PowerShell script which it executed with execution-policy bypass. Later stages compiled and loaded additional code in memory and injected that code into the legitimate timeout.exe process. Microsoft reported that this injection was used for credential theft against browsers and devices.
Persistence: unpacking Python, tar.exe, and a scheduled task
The malware connected to attacker-controlled servers, unpacked a copy of Python using the built-in tar.exe, and created a scheduled task that ran a Python payload through pythonw.exe. Microsoft described this scheduled task as giving attackers a foothold that survived a reboot.
Microsoft Defender Antivirus detects the malicious command execution as Trojan:Win32/ClickFix and Trojan:Win32/TermFix, per the advisory.
Detection, hunting, and Microsoft mitigation guidance
Microsoft recommended a set of defensive measures: turn on cloud-delivered protection, enable network protection, apply application control, and enable PowerShell script-block logging. For hunting, the company advised investigators to look beyond traditional download events and instead examine browser activity, unusual WScript and PowerShell behavior, scheduled-task activity, and the RunMRU registry key, which records entries typed into the Run box.
What this means for technologists, security teams, and end users
- Technologists and security teams: focus on telemetry beyond download events — browser cache activity, RunMRU entries, WScript/Powershell invocations, and scheduled tasks can all show traces of this chain.
- Enterprises and procurement leaders: ensure endpoint controls recommended by Microsoft are enabled — cloud-delivered protection, network protection, application control — and validate logging for PowerShell script blocks and scheduled tasks.
- End users and the general public: treat CAPTCHAs that instruct you to open system dialogs and paste commands as malicious; follow Microsoft's plain guidance that "a CAPTCHA should not ask users to run code."
The ClickFix campaign demonstrates a shift in technique that matters because it relocates the payload onto the disk before any obvious download event occurs, then uses the Run dialog as a simple delivery trigger. That combination — prefetch into cache, size-based selection, and a one-line Run invocation — narrows the window for traditional download-based detection and widens the need for defenders to inspect what users type into Run and what sits in browser caches.
Read the original Microsoft-linked report at https://www.infosecurity-magazine.com/news/clickfix-vbscript-browser-cache/




