ClickFix Fake CAPTCHA Attack Delivers Malware via Browser Cache
Key Takeaways A new ClickFix campaign leverages fake CAPTCHA prompts to trick users into executing malware. The attack pre-stages its primary payload within the victim’s browser cache,...
Key Takeaways
- A new ClickFix campaign leverages fake CAPTCHA prompts to trick users into executing malware.
- The attack pre-stages its primary payload within the victim’s browser cache, disguising it as an image file.
- Victims are instructed to open the Windows Run dialog, paste a command, and press Enter, leading to credential theft and persistent access.
- The technique bypasses traditional security measures focused on direct downloads, highlighting a shift towards human-led infection chains.
- Microsoft Threat Intelligence has documented the multi-stage attack and provided indicators of compromise.
ClickFix Campaign Leverages Browser Cache for Stealthy Malware Delivery
A sophisticated new campaign dubbed “ClickFix” is actively exploiting a seemingly innocuous web security measure to deploy malware. Threat actors are compromising legitimate websites, presenting visitors with deceptive CAPTCHA or system repair messages. These prompts instruct users to open the Windows Run dialog, paste a provided string of text, and then press Enter, initiating a covert malware execution chain.
Table Of Content
The deceptive instruction, while appearing straightforward, ultimately compels the victim to run a command orchestrated by the attackers. What makes this campaign particularly concerning is its method of payload delivery: the core malicious script is not downloaded in an obvious manner. Instead, it is surreptitiously placed within the user’s browser cache prior to the execution step, effectively evading detection mechanisms that typically monitor new file downloads.
Microsoft Threat Intelligence has identified this malicious activity across a cluster of compromised websites. In their published findings, Microsoft detailed how the attackers conceal the pre-fetched script as a PNG file. This disguise is crucial, as it allows for a shorter command string to be used in the Windows Run dialog, reducing suspicion.
The publicly disclosed attack involves multiple stages, primarily aimed at stealing credentials. This design choice can significantly weaken security controls that solely concentrate on newly downloaded files and real-time network requests during execution. The ClickFix campaign also exemplifies a broader trend towards human-orchestrated infection chains, a tactic previously observed in browser cache smuggling reports, where a seemingly routine user prompt becomes the gateway to credential theft and persistent system access.
Fake CAPTCHA Prompts Lead to Malware Execution
The attack sequence begins when a user navigates to a website that has been compromised. A fraudulent verification or repair panel then appears, urging the user to invoke the Windows Run dialog (Win+R), paste content from their clipboard, and execute it. It is critical to note that legitimate CAPTCHA verification processes always remain within the browser environment and never require a user to execute system-level commands.
Behind the scenes, the VBScript payload has already been discreetly stored within the browser’s profile cache, masquerading as a PNG-like resource. The command pasted by the victim then initiates a command processor. This processor searches cache files in specific locations, such as the Firefox profile folder, comparing their sizes against a value predefined by the attackers.
Upon locating a file with a matching size, the command copies the cached content into a temporary VBScript file, subsequently executing it via the Windows Script Host. To minimize detection, both output and error messages are suppressed, leaving fewer traces of the malicious activity. The expected file size varies between different attack variants, rendering static size-based detection rules ineffective.
This “split-stage” approach offers several advantages to the attackers: it circumvents the need to embed a lengthy script directly into the Run dialog, and it eliminates the requirement to fetch the main payload after the victim has already taken action. Previous analyses of fake CAPTCHA phishing tactics underscore the efficacy of this model, which leverages user trust in security checks and offloads the execution burden onto the user. Microsoft Threat Intelligence highlighted this activity on October 3, 2026, providing a visual representation: pic.twitter.com/DcbZQozZoI.
The VBScript component proceeds to gather detailed device information using Windows Management Instrumentation (WMI) and then retrieves a PowerShell script. Subsequent stages involve downloading an additional payload, invoking .NET compilation tools, and launching a legitimate Windows utility. Further malicious code is then loaded into memory and injected into this legitimate process, with the ultimate goal of exfiltrating browser-stored and device credentials.
Credential Theft and Persistence
Beyond initial credential harvesting, the ClickFix campaign also aims to establish persistence on the compromised device. This is achieved by modifying the current user’s PowerShell execution policy to “Bypass,” unpacking Python components, and creating a scheduled task. This task is configured to launch a Python payload through a windowless interpreter, ensuring it runs silently in the background.
These sophisticated steps provide attackers with a robust mechanism to regain access even after the user closes their browser. Security teams must therefore expand their vigilance beyond conventional download alerts. Key areas for investigation include unusual browser-cache activity, modifications to the RunMRU registry key, suspicious child processes originating from WScript or PowerShell, and the creation of new scheduled tasks. Similar FileFix cache smuggling attacks have previously demonstrated how concealing payloads within seemingly harmless browser content can significantly reduce visible network activity.
What You Should Do
- Enable Cloud-Delivered Protection: Implement and maintain up-to-date cloud-delivered protection, web protection, and network protection solutions.
- Implement Application Control: Utilize application control policies to restrict the execution of unauthorized scripts and executables.
- Enable PowerShell Script-Block Logging: Configure PowerShell script-block logging to capture and monitor suspicious activity within PowerShell.
- Investigate Suspicious Alerts: Actively investigate any alerts related to suspicious command execution or outbound connections from user endpoints.
- Educate Users: Train users to never paste commands into system prompts like Run, Terminal, or PowerShell when instructed by a website, even if it appears to be a security verification. Emphasize that legitimate CAPTCHA checks do not require command-line access.
- Monitor for Persistence Mechanisms: Regularly audit scheduled tasks and registry keys (like RunMRU) for unauthorized entries.
- Review Browser Cache Activity: Monitor for unusual activity within browser cache directories, particularly for executables or scripts disguised as other file types.
The primary defense against this type of attack remains straightforward: legitimate CAPTCHA checks never require command-line access. The success of this campaign hinges on victims accepting instructions that take them outside the browser environment, rather than merely viewing a malicious page. Recognizing this critical boundary can prevent the initial command from executing, even if the payload has already been cached. While these findings detail a credential-focused intrusion chain, Microsoft did not disclose a victim count or identify the specific operators involved in this particular disclosure. It is important to remember that even with cache staging, the activity is not entirely invisible; suspicious script execution, anomalous process relationships, outbound network connections, and persistence changes still offer crucial opportunities for detection and investigation.
Indicators of Compromise (IoCs):-
Note:IP addresses and domains are intentionally defanged (e.g.,[.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.