VMTech
Discuss a project →

Microsoft Details ClickFix Browser Cache Smuggling Technique

Microsoft Details ClickFix Browser Cache Smuggling Technique

Microsoft Threat Intelligence has identified a ClickFix attack technique in which compromised websites pre-fetch a malicious script into a browser cache while disguising it as a PNG file. The approach lets attackers persuade a victim to paste a shorter command into Windows Run, whose input is truncated at roughly 260 characters, while the substantive payload is already present on the device.

Rather than downloading a remote payload directly after the command is executed, the observed chain uses a staged VBScript to invoke cmd.exe and recursively enumerate files beginning with f_ in browser-profile locations such as %LOCALAPPDATA%\Mozilla\Firefox\Profiles. It compares file byte lengths against an expected value and copies a matching cache entry to %LOCALAPPDATA%\Temp\t.vbs, then launches it with wscript.exe.

Cache entries become the delivery mechanism

Microsoft said the expected file size differs between variants. This changes the recovery method from prior approaches that searched cached content for a marker: the attacker identifies the staged object by size, assigns it a VBScript extension and suppresses copy output and errors before execution.

The script also collects host information through Windows Management Instrumentation and fetches a PowerShell script named v.ps1 from an external server. That script retrieves an intermediate PowerShell payload, downloads cab.dat, and reads and executes its contents in a hidden window. Later stages load .NET assemblies in memory and inject code into a newly launched legitimate Windows process, timeout.exe, to target browser and device credentials.

The pattern extends the ClickFix chains outlined in ClickFix attack chains and emerging tactics by shifting more of the payload staging into a local browser cache while retaining the crucial social-engineering step. Microsoft noted that cache smuggling has appeared in ClickFix before; Expel documented an October 2025 campaign that delivered a malware-laced ZIP archive, later identified as an Intrinsec red-team engagement.

Why the user interaction remains central

ClickFix lures typically present a fake CAPTCHA, browser update, error or technical problem and tell the target to copy and paste a command into Windows Run, PowerShell, Windows Terminal or another trusted utility. This technique relies on the user to initiate execution, allowing attackers to abuse built-in system components instead of persuading users to open an unfamiliar executable.

Microsoft recommends cloud-delivered, web and network protection, application control, and PowerShell script-block logging. It also advises security teams to look beyond download events and investigate suspicious browser activity, RunMRU registry entries, WScript or PowerShell child processes, and scheduled tasks. For businesses, the practical implication is to make “never paste commands from a verification prompt” an explicit user rule and pair that guidance with detections for the process and registry activity that follows a ClickFix lure.

#cybersecurity#clickfix#malware#windowssecurity
Open analytics
On the site 0 views
min read 3 06.10.2026
Instagram

Microsoft Details ClickFix Browser Cache Smuggling Technique

Open the post on Instagram ↗