Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The UK has a food waste problem and a food poverty problem – and we have a plan to fix them both | Charlotte Hill

    October 6, 2026

    UK events firm that hosts arms fairs and comic shows sold to rival for £2bn | Informa

    October 6, 2026

    France braces for national day of student protests after injuries and mass arrests

    October 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The UK has a food waste problem and a food poverty problem – and we have a plan to fix them both | Charlotte Hill
    • UK events firm that hosts arms fairs and comic shows sold to rival for £2bn | Informa
    • France braces for national day of student protests after injuries and mass arrests
    • Badenoch denies ‘British Iron Dome’ plan – after Tories use phrase in press release | Kemi Badenoch
    • This remote-controlled wagon is silly but so very useful
    • Reka Releases Rho-1: A 19B Omni-Reasoning Model That Understands, Generates Video and Outputs Robot Actions in One
    • Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
    • Better Markets Says CFTC Is ‘Wrong Agency’ for Retail Crypto
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, October 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 6, 2026 Cybersecurity No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser’s cache.

    “Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file,” the Microsoft Threat Intelligence team said in a post on X.

    Thus, when the victim is prompted to paste and execute a malicious command — as is the case with ClickFix attacks – it executes the cached website content that’s already on the device.

    What’s notable about this browser cache smuggling approach is that it allows the attackers to conceal the payload script and bypass the character limit restrictions. The Windows Run dialog, triggered by Win + R, truncates any input that exceeds approximately 260 characters.

    In the attack chain observed by Microsoft, the staged payload is a Visual Basic Script (VBScript), which then invokes “cmd.exe” to recursively enumerate files whose names start with “f_” in the browser’s profile folder such as “%LOCALAPPDATA%MozillaFirefoxProfiles.”

    “It compares each file’s byte length with an expected value,” Microsoft explained. “Rather than searching for a marker within the contents like previous attacks, it copies a size-matching cache entry to %LOCALAPPDATA%Tempt.vbs, giving the cached payload a VBScript extension, then executes it with wscript.exe. Copy output and errors are suppressed. The expected size varies across variants.”

    The VBScript is also designed to harvest host information via Windows Management Instrumentation (WMI), fetch a PowerShell script (“v.ps1”) from an external server (“cocojambo[.]us[.]com/alfa”), and then launch it. The PowerShell script serves as a conduit for an intermediate PowerShell payload that’s responsible for downloading the next stage (“cab.dat”).

    Cybersecurity

    Once the file is downloaded, its contents are read and executed in a hidden window. The attack eventually paves the way for .NET assemblies that are loaded into memory and inject code into a newly launched legitimate Windows process (“timeout.exe“) with an aim to target browser and device credentials.

    What’s more, the injected process launches PowerShell to obtain a secondary in-memory stage from “capsysnet[.]vg” and initiate outbound connections to “ciliabula[.]cc.”

    This is not the first time payloads have been staged in the browser cache as part of ClickFix attacks. In October 2025, Expel documented an attack chain that employed cache smuggling to deliver a malware-laced ZIP archive. The activity was subsequently identified as a red team engagement conducted by Intrinsec.

    ClickFix has become an exceedingly popular social engineering technique over the past two years. The fact that the attack turns the victim into a delivery channel for executing malware has made it an attractive initial access method for cybercriminals and nation-state actors alike.

    In a proof-of-concept (PoC) exploit released in August 2025, CloudSEK demonstrated how artificial intelligence (AI) summarization systems embedded in email clients, browser extensions, and productivity platforms can be weaponized to deliver ransomware via ClickFix.

    Specifically, the payloads are embedded within HTML content using CSS-based obfuscation methods, such as zero-width characters, white-on-white text, and off-screen positioning, that make them invisible to the human eye, but are parsed by AI systems. This invisible prompt injection is then used to generate summaries containing attacker-controlled ClickFix instructions.

    The attack employs a method known as prompt overdose to repeat the payload dozens of times so that it dominates the model’s context window and steers output generation.

    “When such crafted content is indexed, shared, or emailed, any automated summarization process that ingests it will produce summaries containing attacker-controlled ClickFix instructions,” CloudSEK said. “The observed outcome confirms that prompt overdose in conjunction with invisible injection can successfully override legitimate context within summarizers.”

    The ClickFix ecosystem has evolved considerably since its early days, fueled by the availability of phishing kits like IUAM that can automate the creation of “Fix-type” attacks. The commoditization has further lowered the barrier to entry and accelerated the frequency of these campaigns.

    The anatomy of a ClickFix attack is a multi-step chain –

    • Lead victims to a fake (or compromised) website that hosts the ClickFix lure either via phishing emails or malvertising.
    • Serve the problem trigger (e.g., fake error, CAPTCHA, or browser update)
    • Provide the “solution” and instruct the user to copy a command to address it. Select variants use JavaScript to manipulate the system’s clipboard and copy the command.
    • The user is then asked to paste the copied command into the Windows Run dialog, PowerShell, Windows Terminal, macOS Terminal, or another trusted system utility.
    • The command retrieves additional payloads, leading to malware deployment.

    According to CrowdStrike, incidents involving fake CAPTCHA lures have witnessed a staggering 563% increase in 2025.

    ClickFix is effective because it persuades users to run attacker-supplied commands under the pretext of CAPTCHA verifications, browser updates, or unexpected errors — situations users routinely encounter. The attack capitalizes on this “troubleshooting” theme to trick them into infecting their own systems, effectively bypassing security controls.

    “Employees regularly deal with broken meetings, authentication challenges, CAPTCHA prompts, browser errors, and application issues,” CrowdStrike said. “A prompt telling someone to perform a quick troubleshooting step can feel far less suspicious than an unexpected executable or email attachment.”

    Another reason why ClickFix works is that it relies on standard tools users have come to trust. Rather than asking users to download an unfamiliar program that may raise suspicion, it leverages built-in components of Windows and Mac, such as PowerShell, Windows Run, and Terminal, to activate the attack chain.

    “ClickFix attacks combine psychological manipulation with the abuse of legitimate operating-system tools,” Bob Erdman, associate vice president of research and development at Fortra, said. “The dangerous part is that you execute the command yourself. Instead of breaking into the computer directly, the attacker convinces you to open the door.”

    In one campaign analyzed by CTM360, threat actors have been observed leveraging known vulnerabilities in WordPress plugins (e.g., CVE-2026-6854) to seize control of websites and inject ClickFix lures. The injected script then employs the EtherHiding technique to retrieve the active lure hostname.

    The blockchain-based mechanism offers additional advantages in that an attacker can make on-chain updates to facilitate infrastructure rotation without modifying the compromised site. More than 3,000 actively compromised websites have been identified as hosting fake pages, per CTM360, with the attack chains leading to Vidar Stealer.

    Cybersecurity

    “ClickFix presents fewer malware signals of the sort that traditional defenses are calibrated to detect,” ReversingLabs said in a July 2026 report. “Campaigns play out quickly, with shifting infrastructure intended to evade detection based on historic indicators.”

    CrowdStrike, for its part, said it observed the North Korea-aligned Stardust Chollima (aka BlueNoroff) cluster likely targeting an employee at a financial services entity in July 2026 using a bogus video conferencing site. Upon visiting the site, the employee is said to have encountered a fake technical issue along with a fix that instructed them to copy and paste a command.

    The command is designed to trigger a PowerShell- and VBScript-based infection chain that delivers two previously undocumented malware families dubbed GeniexLoader and GeniexRAT.

    Another nation-state threat actor linked to the use of ClickFix is Sandworm. The Russian state-sponsored adversary has been observed targeting suspected Ukrainian employees working at organizations in France, the U.S., and Canada with ClickFix attacks to deceive them into running PowerShell commands that download a VBScript payload. It’s suspected that the ClickFix lures were delivered via compromised Ukrainian websites.

    To counter the threat, Microsoft is recommending cloud-delivered, web, and network protection, application control, and PowerShell script-block logging. It’s also urging organizations to go beyond download events and hunt for suspicious browser activity, RunMRU registry key, WScript/PowerShell child processes, and scheduled tasks.

    “A CAPTCHA should not ask users to run code,” it added. “Users should not paste commands from verification prompts into Run, Terminal or PowerShell and should treat such requests as potential initial access attempts.”

    browser Bypass cache ClickFix limits Payloads Run Smuggles Windows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

    Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

    UK oil refinery broke toxic pollution limits dozens of times

    Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    South Korea probes bank breaches amid suspected AI-powered attacks

    New Dell System Update flaw lets hackers gain root privileges

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The UK has a food waste problem and a food poverty problem – and we have a plan to fix them both | Charlotte Hill

    October 6, 2026

    UK events firm that hosts arms fairs and comic shows sold to rival for £2bn | Informa

    October 6, 2026

    France braces for national day of student protests after injuries and mass arrests

    October 6, 2026

    Badenoch denies ‘British Iron Dome’ plan – after Tories use phrase in press release | Kemi Badenoch

    October 6, 2026
    Latest Posts

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The UK has a food waste problem and a food poverty problem – and we have a plan to fix them both | Charlotte Hill

    October 6, 2026

    UK events firm that hosts arms fairs and comic shows sold to rival for £2bn | Informa

    October 6, 2026

    France braces for national day of student protests after injuries and mass arrests

    October 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.