Cybersecurity researchers have uncovered an advanced form of the ClickFix attack methodology, where malicious actors exploit cache smuggling to evade traditional file download detection mechanisms. This innovative campaign targets corporate networks, pretending to be a Fortinet, specifically exploiting the trust that organizations place in their remote access infrastructure.
See also: Lazarus APT uses ClickFix technique to steal data

The malicious website, hosted on the fc-checker[.]dlccdn[.]com, presents itself as a legitimate enterprise security tool designed to check VPN compliance in corporate environments. The attack represents a significant departure from conventional ClickFix variants that typically rely on direct file downloads or explicit communication over the internet.
Instead, attackers have developed a method that proactively stores malicious payloads within the browser's cache system, effectively bypassing many security checks that monitor file downloads and network communications. Expel analysts noted that this technique represents a worrying advance in social engineering tactics, particularly as it targets Fortinet VPN clients that are primarily used by enterprises for secure remote access.
See also: New ClickFix attack imitates AnyDesk and distributes MetaStealer

What makes this campaign particularly dangerous is its ability to appear as if users are executing files that already exist on their corporate network. The website displays a text box containing what appears to be a typical network file path: “\\Public\\Support\\VPN\\ForticlientCompliance.exe“. However, beneath this appearance of legitimacy, lies a complex PowerShell designed to extract and execute malicious code from the browser cache without making any external network connections.
The technical sophistication of this attack centers on the implementation of cache smuggling, which represents a novel approach to payload delivery. When users interact with the malicious website, a disguised JavaScript function performs a fetch request to “/5b900a00-71e9-45cf-acc0-d872e1d6cdaa“, which is presented as a legitimate JPEG image, setting the HTTP Content-Type header to “image/jpeg”. The browser automatically caches this supposed image, but examination reveals that it does not contain a JPEG header and instead hosts a compressed ZIP file wrapped between unique delimiter strings “bTgQcBpv” and “mX6o0lBw”.
See also: ClickFix attack with fake BBC page and Cloudflare verification

The PowerShell script hidden within the clipboard payload includes a sophisticated regex pattern that searches the Chrome cache directory for these specific delimiters: $m=[regex]::Matches($c,'(?. Once found, the script extracts the data between these markers, writes it to “ComplianceChecker.zip“, extracts the file, and runs “FortiClientComplianceChecker.exe” completely offline. This technique effectively bypasses security solutions that monitor file downloads or PowerShell requests over the internet, as no explicit network activity occurs during the malicious execution phase.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
