Skip to main content
Emerging ThreatsMalware & Ransomware

Microsoft Warns of ClickFix Browser Cache Smuggling Attacks Bypassing Windows Defenses

Person examines paper in cluttered home office, laptop and browser window in background.
"Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre‑fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said.

Microsoft: browser‑cache smuggling bypasses Windows Run limits

Microsoft's analysis describes a refined ClickFix variant that smuggles an attacker script into the victim's browser cache as if it were an image. The technique avoids the usual step of fetching and executing a remote file in real time. Instead, when a victim follows the typical ClickFix instruction to paste and run a command, that command causes the system to execute cached website content already on disk.

That design is deliberate: the Windows Run dialog (Win + R) truncates input that exceeds roughly 260 characters, creating a practical barrier for long, complex payloads. By staging the payload in the browser cache, attackers conceal the script and bypass the Run dialog's character limit.

Technical attack chain observed by Microsoft

Microsoft documented a multi‑stage chain. The staged payload is a Visual Basic Script (VBScript) that performs host reconnaissance via Windows Management Instrumentation (WMI) and then fetches a PowerShell script named "v.ps1" from an external host at "cocojambo[.]us[.]com/alfa". That PowerShell script acts as a loader for an intermediate PowerShell payload that downloads a file called "cab.dat".

Once "cab.dat" is retrieved, the content is read and executed in a hidden window. The chain proceeds to load .NET assemblies into memory and inject code into a legitimate process ("timeout.exe") with the aim of targeting browser and device credentials. The injected process then launches PowerShell to obtain a secondary in‑memory stage from "capsysnet[.]vg" and to initiate outbound connections to "ciliabula[.]cc".

Microsoft also described the cache discovery and execution mechanics: the VBScript enumerates browser profile files (for example under "%LOCALAPPDATA%\\Mozilla\\Firefox\\Profiles"), looks for cache entries whose byte length matches an expected value, copies a size‑matching cache entry to "%LOCALAPPDATA%\\Temp\\t.vbs", and executes it with wscript.exe. Copy output and errors are suppressed.

ClickFix evolution: AI PoCs, commodity kits, and exploited sites

ClickFix is no longer a narrow trick; researchers report it has evolved into a broad ecosystem. CrowdStrike recorded a 563% increase in incidents involving fake CAPTCHA lures in 2025, and CTM360 identified more than 3,000 actively compromised websites hosting fake pages that led to credential‑stealing malware such as Vidar Stealer.

Attackers have combined technical tricks with commoditization. The availability of phishing kits like IUAM automates the creation of Fix‑type lures, lowering the barrier to entry. In October 2025, Expel documented a cache‑smuggling variant that delivered a malware‑laced ZIP — an incident later attributed to a red team engagement by Intrinsec.

Artificial intelligence has been enlisted as well. CloudSEK released a proof‑of‑concept in August 2025 showing how AI summarization systems embedded in email clients, browser extensions, and productivity platforms can be weaponized to produce ClickFix instructions. The PoC used CSS obfuscation (zero‑width characters, white‑on‑white text, off‑screen positioning) plus a “prompt overdose” that repeats payloads to dominate a model’s context window, leading automated summarizers to output attacker‑controlled ClickFix directives.

Nation‑state actors have used ClickFix too. CrowdStrike attributed a July 2026 campaign that used a fake video‑conferencing site to the North Korea‑aligned Stardust Chollima cluster, delivering PowerShell‑ and VBScript‑based chains that dropped two previously undocumented families called GeniexLoader and GeniexRAT. Separately, Sandworm has been observed delivering VBScript via compromised Ukrainian websites to target suspected Ukrainian employees in France, the U.S., and Canada.

CTM360 also reported that threat actors leveraged a WordPress plugin vulnerability (CVE‑2026‑6854) to seize sites and inject ClickFix lures, and used an on‑chain retrieval technique called EtherHiding to rotate infrastructure without modifying the compromised page.

Defender guidance from Microsoft, vendors, and analysts

Microsoft's recommended mitigations include cloud‑delivered web and network protection, application control, and PowerShell script‑block logging. It urged defenders to go beyond simple download event logging and hunt for suspicious browser activity, RunMRU registry entries, WScript/PowerShell child processes, and anomalous scheduled tasks. Microsoft added blunt user guidance: "A CAPTCHA should not ask users to run code," and "Users should not paste commands from verification prompts into Run, Terminal or PowerShell and should treat such requests as potential initial access attempts."

Analysts and vendors reinforced the operational risk. ReversingLabs warned that ClickFix "presents fewer malware signals of the sort that traditional defenses are calibrated to detect" and that campaigns move quickly with shifting infrastructure to evade historic indicators. Bob Erdman of Fortra underscored the human element: ClickFix combines psychological manipulation with abuse of legitimate OS tools so the user effectively becomes the delivery channel.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: prioritize telemetry beyond download events—monitor browser cache access patterns, RunMRU, WScript/PowerShell parent‑child relationships, scheduled task creation, and enable PowerShell script‑block logging as Microsoft advises.
  • Affected enterprises and procurement leaders: patch and monitor web infrastructure—CTM360 tied widespread lure hosting to compromised sites and a WordPress plugin vulnerability (CVE‑2026‑6854); consider web and cloud controls, and inventory exposure to commodity phishing kits like IUAM.
  • End users and the general public: follow Microsoft's guidance literally—do not paste code from CAPTCHA or update prompts into Run, Terminal, or PowerShell; treat troubleshooting instructions that request code execution as potential initial access attempts.

ClickFix has graduated from a niche social‑engineering trick to a diversified delivery ecosystem: cache smuggling, AI‑driven summarizer abuse, commodity phishing kits, exploited web infrastructure, and nation‑state adoption. Microsoft’s findings show attackers adapting to platform constraints — here, a 260‑character limit — by moving payloads into places defenders do not typically monitor. The remedy Microsoft prescribes is straightforward but operationally demanding: expand hunting to the browser cache and related artifacts, harden application control and logging, and treat any prompt that asks a user to run code as a red flag.

Original story at The Hacker News