HomeSecurityHackers Upgraded ClickFix Attack with Cache Smuggling

Hackers upgraded ClickFix attack with Cache Smuggling

Cybersecurity researchers have uncovered an advanced form of the ClickFix attack methodology, where malicious actors exploit cache smuggling to evade traditional file download detection mechanisms. This innovative campaign targets corporate networks, pretending to be a Fortinet, specifically exploiting the trust that organizations place in their remote access infrastructure.

See also: Lazarus APT uses ClickFix technique to steal data

ClickFix cache smuggling

The malicious website, hosted on the fc-checker[.]dlccdn[.]com, presents itself as a legitimate enterprise security tool designed to check VPN compliance in corporate environments. The attack represents a significant departure from conventional ClickFix variants that typically rely on direct file downloads or explicit communication over the internet.

Instead, attackers have developed a method that proactively stores malicious payloads within the browser's cache system, effectively bypassing many security checks that monitor file downloads and network communications. Expel analysts noted that this technique represents a worrying advance in social engineering tactics, particularly as it targets Fortinet VPN clients that are primarily used by enterprises for secure remote access.

See also: New ClickFix attack imitates AnyDesk and distributes MetaStealer

Hackers upgraded ClickFix attack with Cache Smuggling

What makes this campaign particularly dangerous is its ability to appear as if users are executing files that already exist on their corporate network. The website displays a text box containing what appears to be a typical network file path: “\\Public\\Support\\VPN\\ForticlientCompliance.exe“. However, beneath this appearance of legitimacy, lies a complex PowerShell designed to extract and execute malicious code from the browser cache without making any external network connections.

The technical sophistication of this attack centers on the implementation of cache smuggling, which represents a novel approach to payload delivery. When users interact with the malicious website, a disguised JavaScript function performs a fetch request to “/5b900a00-71e9-45cf-acc0-d872e1d6cdaa“, which is presented as a legitimate JPEG image, setting the HTTP Content-Type header to “image/jpeg”. The browser automatically caches this supposed image, but examination reveals that it does not contain a JPEG header and instead hosts a compressed ZIP file wrapped between unique delimiter strings “bTgQcBpv” and “mX6o0lBw”.

See also: ClickFix attack with fake BBC page and Cloudflare verification

Hackers upgraded ClickFix attack with Cache Smuggling

The PowerShell script hidden within the clipboard payload includes a sophisticated regex pattern that searches the Chrome cache directory for these specific delimiters: $m=[regex]::Matches($c,'(?. Once found, the script extracts the data between these markers, writes it to “ComplianceChecker.zip“, extracts the file, and runs “FortiClientComplianceChecker.exe” completely offline. This technique effectively bypasses security solutions that monitor file downloads or PowerShell requests over the internet, as no explicit network activity occurs during the malicious execution phase.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS