Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Google Gemini AI to gain full computer access: What it means for users
October 5, 2026
ClickFix Fake CAPTCHA Attack Delivers Malware via Browser Cache
October 5, 2026
RemoveMacAI Tool Deletes Apple Intelligence Models, Frees 12GB Storage
October 5, 2026
Home/Threats/ClickFix Fake CAPTCHA Attack Delivers Malware via Browser Cache
Threats

ClickFix Fake CAPTCHA Attack Delivers Malware via Browser Cache

Key Takeaways A new ClickFix campaign leverages fake CAPTCHA prompts to trick users into executing malware. The attack pre-stages its primary payload within the victim’s browser cache,...

Jennifer sherman
Jennifer sherman
October 5, 2026 5 Min Read
2 0

Key Takeaways

  • A new ClickFix campaign leverages fake CAPTCHA prompts to trick users into executing malware.
  • The attack pre-stages its primary payload within the victim’s browser cache, disguising it as an image file.
  • Victims are instructed to open the Windows Run dialog, paste a command, and press Enter, leading to credential theft and persistent access.
  • The technique bypasses traditional security measures focused on direct downloads, highlighting a shift towards human-led infection chains.
  • Microsoft Threat Intelligence has documented the multi-stage attack and provided indicators of compromise.

ClickFix Campaign Leverages Browser Cache for Stealthy Malware Delivery

A sophisticated new campaign dubbed “ClickFix” is actively exploiting a seemingly innocuous web security measure to deploy malware. Threat actors are compromising legitimate websites, presenting visitors with deceptive CAPTCHA or system repair messages. These prompts instruct users to open the Windows Run dialog, paste a provided string of text, and then press Enter, initiating a covert malware execution chain.

Table Of Content

  • Key Takeaways
  • ClickFix Campaign Leverages Browser Cache for Stealthy Malware Delivery
  • Fake CAPTCHA Prompts Lead to Malware Execution
  • Credential Theft and Persistence
  • What You Should Do

The deceptive instruction, while appearing straightforward, ultimately compels the victim to run a command orchestrated by the attackers. What makes this campaign particularly concerning is its method of payload delivery: the core malicious script is not downloaded in an obvious manner. Instead, it is surreptitiously placed within the user’s browser cache prior to the execution step, effectively evading detection mechanisms that typically monitor new file downloads.

Microsoft Threat Intelligence has identified this malicious activity across a cluster of compromised websites. In their published findings, Microsoft detailed how the attackers conceal the pre-fetched script as a PNG file. This disguise is crucial, as it allows for a shorter command string to be used in the Windows Run dialog, reducing suspicion.

The publicly disclosed attack involves multiple stages, primarily aimed at stealing credentials. This design choice can significantly weaken security controls that solely concentrate on newly downloaded files and real-time network requests during execution. The ClickFix campaign also exemplifies a broader trend towards human-orchestrated infection chains, a tactic previously observed in browser cache smuggling reports, where a seemingly routine user prompt becomes the gateway to credential theft and persistent system access.

Fake CAPTCHA Prompts Lead to Malware Execution

The attack sequence begins when a user navigates to a website that has been compromised. A fraudulent verification or repair panel then appears, urging the user to invoke the Windows Run dialog (Win+R), paste content from their clipboard, and execute it. It is critical to note that legitimate CAPTCHA verification processes always remain within the browser environment and never require a user to execute system-level commands.

Behind the scenes, the VBScript payload has already been discreetly stored within the browser’s profile cache, masquerading as a PNG-like resource. The command pasted by the victim then initiates a command processor. This processor searches cache files in specific locations, such as the Firefox profile folder, comparing their sizes against a value predefined by the attackers.

Upon locating a file with a matching size, the command copies the cached content into a temporary VBScript file, subsequently executing it via the Windows Script Host. To minimize detection, both output and error messages are suppressed, leaving fewer traces of the malicious activity. The expected file size varies between different attack variants, rendering static size-based detection rules ineffective.

This “split-stage” approach offers several advantages to the attackers: it circumvents the need to embed a lengthy script directly into the Run dialog, and it eliminates the requirement to fetch the main payload after the victim has already taken action. Previous analyses of fake CAPTCHA phishing tactics underscore the efficacy of this model, which leverages user trust in security checks and offloads the execution burden onto the user. Microsoft Threat Intelligence highlighted this activity on October 3, 2026, providing a visual representation: pic.twitter.com/DcbZQozZoI.

The VBScript component proceeds to gather detailed device information using Windows Management Instrumentation (WMI) and then retrieves a PowerShell script. Subsequent stages involve downloading an additional payload, invoking .NET compilation tools, and launching a legitimate Windows utility. Further malicious code is then loaded into memory and injected into this legitimate process, with the ultimate goal of exfiltrating browser-stored and device credentials.

Credential Theft and Persistence

Beyond initial credential harvesting, the ClickFix campaign also aims to establish persistence on the compromised device. This is achieved by modifying the current user’s PowerShell execution policy to “Bypass,” unpacking Python components, and creating a scheduled task. This task is configured to launch a Python payload through a windowless interpreter, ensuring it runs silently in the background.

These sophisticated steps provide attackers with a robust mechanism to regain access even after the user closes their browser. Security teams must therefore expand their vigilance beyond conventional download alerts. Key areas for investigation include unusual browser-cache activity, modifications to the RunMRU registry key, suspicious child processes originating from WScript or PowerShell, and the creation of new scheduled tasks. Similar FileFix cache smuggling attacks have previously demonstrated how concealing payloads within seemingly harmless browser content can significantly reduce visible network activity.

What You Should Do

  • Enable Cloud-Delivered Protection: Implement and maintain up-to-date cloud-delivered protection, web protection, and network protection solutions.
  • Implement Application Control: Utilize application control policies to restrict the execution of unauthorized scripts and executables.
  • Enable PowerShell Script-Block Logging: Configure PowerShell script-block logging to capture and monitor suspicious activity within PowerShell.
  • Investigate Suspicious Alerts: Actively investigate any alerts related to suspicious command execution or outbound connections from user endpoints.
  • Educate Users: Train users to never paste commands into system prompts like Run, Terminal, or PowerShell when instructed by a website, even if it appears to be a security verification. Emphasize that legitimate CAPTCHA checks do not require command-line access.
  • Monitor for Persistence Mechanisms: Regularly audit scheduled tasks and registry keys (like RunMRU) for unauthorized entries.
  • Review Browser Cache Activity: Monitor for unusual activity within browser cache directories, particularly for executables or scripts disguised as other file types.

The primary defense against this type of attack remains straightforward: legitimate CAPTCHA checks never require command-line access. The success of this campaign hinges on victims accepting instructions that take them outside the browser environment, rather than merely viewing a malicious page. Recognizing this critical boundary can prevent the initial command from executing, even if the payload has already been cached. While these findings detail a credential-focused intrusion chain, Microsoft did not disclose a victim count or identify the specific operators involved in this particular disclosure. It is important to remember that even with cache staging, the activity is not entirely invisible; suspicious script execution, anomalous process relationships, outbound network connections, and persistence changes still offer crucial opportunities for detection and investigation.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain/path cocojambo[.]us[.]com/alfa Location from which the initial VBScript retrieves a PowerShell script.
Domain capsysnet[.]vg Source of an additional memory-resident stage.
Domain ciliabula[.]cc Destination of outbound connections from the injected process.
File path %LOCALAPPDATA%Tempt.vbs Temporary VBScript payload copied from a matching browser-cache entry.
File name v.ps1 PowerShell script retrieved by the VBScript stage.
File name cab.dat Downloaded next-stage payload whose contents are subsequently executed.
File name prefix f_ Prefix used to select cache-file candidates before comparing their byte lengths.
Directory %LOCALAPPDATA%MozillaFirefoxProfiles Example browser-profile directory searched for cached payload content.
Executable cmd.exe Legitimate command processor abused to enumerate and copy cached files; not malicious by itself.
Executable wscript.exe Legitimate Windows Script Host executable used to launch the temporary VBScript.
Executable csc.exe Legitimate .NET compilation tool invoked during the attack chain.
Executable cvtres.exe Legitimate resource-conversion tool involved in the observed .NET compilation activity.
Executable timeout.exe Legitimate Windows utility targeted for code injection.
Executable tar.exe Legitimate archive utility used to unpack Python components.
Executable pythonw.exe Legitimate windowless Python interpreter used by the persistence task.

Note:IP addresses and domains are intentionally defanged (e.g.,[.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

RemoveMacAI Tool Deletes Apple Intelligence Models, Frees 12GB Storage

Next Post

Google Gemini AI to gain full computer access: What it means for users

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Pauses Open-Source Bug Bounty Program Due to AI-Generated Spam
October 5, 2026
Windows 11 KB5124010 Update Crashes Productivity Apps and Games
October 5, 2026
ConnectWise ScreenConnect Critical Vulnerability Exploited by Attackers
October 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us