HomeSecurityClickFix: Hides payloads in the browser cache

ClickFix: Hides payloads in the browser cache

The ClickFix technique is evolving in a dangerous way: Microsoft Threat Intelligence researchers have identified a new variant that uses the browser cache to store malicious payloads, thereby bypassing the character restrictions of the Windows Run dialog . Instead of downloading the payload at the time of execution, the attacker “pre-loads” it into the victim’s cache, disguised as a PNG file . This is an advanced social engineering technique that makes it even more difficult to detect by traditional security tools.

See also: Hackers upgraded ClickFix attack with Cache Smuggling

ClickFix cache smuggling browser payload Windows attack

ClickFix has become one of the most prevalent attack techniques over the past two years. Its basic logic is simple but effective: the user visits a compromised website, sees a fake CAPTCHA or browser verification message, and is convinced to execute commands that the attacker has placed in the clipboard. The page prompts the user to press Win + R , paste the command, and press Enter — thus using the operating system’s own tools against them. According to data from Microsoft Defender Experts , 47% of initial access incidents handled in 2025 were attributed to ClickFix, while ESET reported a 517% increase in the first half of 2025 and an additional 108% increase from the second half of 2025 to the first half of 2026.

The new variant described by Microsoft in early October 2026 introduces a critical technical innovation. The Windows Run dialog, which is activated with Win + R, truncates any input exceeding approximately 260 characters. This was a practical obstacle for attackers, who could not embed the entire malicious script in the clipboard. The new method solves this problem: the compromised website pre-loads the payload into the browser cache before the user follows the instructions, and the short command that is pasted simply locates and executes the already cached file.

How ClickFix works with cache smuggling

In the attack chain observed by Microsoft, the staged payload is a Visual Basic Script (VBScript). The ClickFix payload searches for files in the browser profile folder — for example, in the path %LOCALAPPDATA%\Mozilla\Firefox\Profiles — using cmd.exe to recursively enumerate files that start with f_. It then compares the size of each file in bytes with an expected value. When the correct file is found, it is copied to %LOCALAPPDATA%\Temp\t.vbs and executed via wscript.exe. Error messages and the output of the copy command are suppressed so that the user does not notice anything suspicious.

The executed VBScript is designed to collect information about the host computer via Windows Management Instrumentation (WMI) , retrieve a PowerShell script (v.ps1) from an external server, and launch it. The PowerShell script acts as a conduit for an intermediate payload that downloads the next stage (cab.dat). Once the file is downloaded, its contents are read and executed in a hidden window. The attack results in loading .NET assemblies into memory and injecting code into a legitimate Windows process (timeout.exe), with the goal of stealing browser and device credentials. The compromised process also launches PowerShell to acquire a secondary in-memory stage and initiate outbound connections to external servers.

It’s worth noting that cache staging is not entirely new. In October 2025, Expel documented an attack chain that used cache smuggling to deliver a malware- laden ZIP file . This activity was later identified as a red team engagement conducted by Intrinsec . Recent reports also link similar ClickFix techniques to the DOUBLECUP loader-as-a-service operation, which uses PNG files cached by browsers to deliver CountLoader and, on Windows systems , a remote-access trojan called DeviceManager .

See also: ClickFix: Analysis of 3,000 payloads reveals API-driven malware

cache smuggling - SecNews.gr

ClickFix and AI: The next evolution of the threat

The evolution of ClickFix doesn’t stop at cache smuggling. In August 2025, CloudSEK published a proof-of-concept (PoC) exploit that demonstrated how artificial intelligence ( AI ) digest systems built into email clients, browser extensions, and productivity platforms can be used to deliver ransomware via ClickFix. The payloads are embedded in HTML content using CSS- based obfuscation methods , such as zero-width characters, white text on a white background, and off-screen positioning — invisible to the human eye, but parseable by AI systems. This invisible prompt injection is then used to generate digests containing attacker-controlled ClickFix instructions.

The attack uses a method known as prompt overdose, repeating the payload dozens of times to dominate the model’s context window and guide the output production. When such content is indexed, shared, or emailed, any automated summarization process that processes it will produce summaries containing ClickFix instructions controlled by the attacker, according to CloudSEK. This development makes ClickFix even more dangerous, as it extends the attack surface to tools that users consider reliable helpers.

In a broader context, a September 2026 investigation identified approximately 17,000 URLs associated with ClickFix-style copy-and-paste lures, demonstrating that the technique is distributed through widespread website hacking and malvertising, and not just targeted phishing. CrowdStrike characterizes ClickFix as a security-boundary attack: the website does not necessarily exploit the browser or Windows directly, but convinces the user to copy attacker-controlled content to a trusted operating system interface. This makes traditional control measures less effective, as the resulting process can appear to be initiated by the user.

How to protect yourself from ClickFix

Microsoft is clear in its guidance: a legitimate CAPTCHA or browser verification page will never ask a user to paste commands into Run, Command Prompt, Terminal, or PowerShell . Organizations should educate their users about this tactic and consider disabling or restricting the Windows Run dialog for standard users where functionally feasible. Implementing application control policies such as AppLocker or Windows Defender Application Control to restrict executables such as wscript.exe , cscript.exe , mshta.exe , powershell.exe , cmd.exe , and curl.exe — particularly from user-writable directories — is a critical defense.

See also: 17,000 URLs reveal how ClickFix turns trusted websites into malware traps

ClickFix API-driven malware delivery 3000 payloads analysis

Additionally, it is recommended to enable PowerShell script-block logging and push relevant Windows to a SIEM. Security teams should monitor process chains where browsers launch cmd.exe, wscript.exe , or PowerShell, and be alerted to scripts launched from the %TEMP%. Implementing cloud-delivered protection, web protection, network protection, and application control policies recommended by Microsoft provides additional layers of defense. Finally, regular security awareness training remains the most effective line of defense, as ClickFix relies entirely on user deception rather than technical exploitation of software vulnerabilities. The technique continues to evolve and pose a serious threat to organizations and individuals worldwide.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS