ClickFix Attack Hides VBScript Payload in Browser Cache
A ClickFix campaign has been observed hiding a VBScript payload in the browser cache, disguised as an image, so the script was already on the device when the victim was tricked into running a command through Windows Run.
Microsoft Threat Intelligence described the technique in a post on X on October 3, saying a cluster of compromised websites was leading visitors to the attacks.
ClickFix is a social engineering technique that gets victims to run attacker-supplied commands under the guise of a verification step. In this campaign, a fake CAPTCHA pop-up told users to open Run, paste from their clipboard and press Enter.
Rather than downloading the payload after the victim acted, the sites pre-fetched it into the browser cache. Microsoft said this helped hide the script and bypass the Run dialog's character limit, since the pasted command only had to find and launch a file already on disk.
Browser Cache Hides the Payload
The pasted command ran cmd.exe, which searched the browser profile folder for cached files whose names began with "f_" and compared each file's size with an expected value.
Rather than searching the cached content for a marker, as earlier attacks did, Microsoft said this one matched on size, copied the file to a temporary folder with a .vbs extension and ran it with wscript.exe.
The VBScript gathered host details through Windows Management Instrumentation (WMI), then fetched a PowerShell script and ran it with the execution policy bypassed. Later stages compiled and loaded further code in memory, injecting it into the legitimate timeout.exe process for credential theft against browsers and devices.
Read more on ClickFix: ClickFix Now Cybercriminals' Favorite Malware Delivery Technique
Persistence Through a Scheduled Task
The malware then connected to attacker servers, unpacked a copy of Python using the built-in tar.exe and created a scheduled task that ran a Python payload through pythonw.exe, giving the attackers a foothold that survived a reboot.
Microsoft Defender Antivirus blocks malicious command execution as Trojan:Win32/ClickFix and Trojan:Win32/TermFix. Microsoft also recommended turning on cloud-delivered protection, network protection, application control and PowerShell script-block logging.
For hunting, it advised looking beyond download events to browser activity, unusual WScript, PowerShell and scheduled-task activity and the RunMRU registry key, which records what users type into the Run box. A CAPTCHA should not ask users to run code, Microsoft added.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.