ClickFix attacks have evolved from simple social-engineering lures into highly creative delivery mechanisms that turn a userâs own system into the execution environment. Recent Microsoft telemetry describes a variant that stages malicious scripts inside a victimâs browser cacheâdisguised as innocuous PNG filesâand then convinces the user to paste a short command that triggers execution of that cached payload. By hiding the payload in cache entries and later reconstituting it on disk, attackers can sidestep character-length constraints in the Windows Run dialog and evade many conventional download-detection signals.
How the cache-smuggling ClickFix works
Microsoft observed compromised sites pre-fetching a script into the browser cache while labeling it as a PNG. Instead of pulling an executable from a remote host at runtime, the attack instructs the victim to paste a command into a trusted tool (e.g., the Run dialog). That command runs a small VBScript that scans the browser profile cache for cache entries with a specific filename pattern and exact byte length, copies a size-matching cache entry to %LOCALAPPDATA%Tempt.vbs, and runs it with wscript.exe. Copy output and errors are suppressed, and the payload thus executes as if it were a local script file.
From there the observed chains typically use VBScript to gather host information (via WMI), fetch an external PowerShell script (v.ps1 from cocojambo[.]us[.]com/alfa in the case Microsoft documented), and launch successive, in-memory stages. The intermediate PowerShell payload downloads a cab.dat file, reads and executes its contents in a hidden window, and ultimately loads .NET assemblies into memory. Those assemblies inject code into a legitimate process (timeout.exe) to harvest browser and device credentials, spawn additional PowerShell to pull a secondary stage from capsysnet[.]vg, and connect out to infrastructure such as ciliabula[.]cc.
Why this technique defeats Windows Run limits and detection
The Windows Run dialog truncates inputs at roughly 260 characters, which limits how much attacker-controlled code can be passed directly via paste-and-execute lures. By pre-staging the heavy payload inside the browser cache and using a tiny oneliners to reconstruct and execute it, adversaries effectively bypass the Run character limit while minimizing observable network artifacts at the time of execution. Because the payload originates from the local cache, defenses that focus on download events or network indicators may miss the critical staging phase. Additionally, ClickFix chains often rely on built-in tools (Run, PowerShell, wscript), which lowers user suspicion and makes behavior-based detection harder when itâs framed as âtroubleshooting.â
Real-world campaigns, threat actors, and historical context
Cache staging in ClickFix is not entirely new: in October 2025 Expel documented a cache-smuggling chain that delivered a malware-laced ZIP, later attributed to a red-team exercise by Intrinsec. But the technique has become more prolific and diverse. CrowdStrike reported dramatic growth in fake CAPTCHA lures through 2025, and analysts have tied ClickFix campaigns to nation-state clusters as well: Microsoft and CrowdStrike linked activity to North Koreaâaligned Stardust Chollima (BlueNoroff) and to Russian-aligned Sandworm in separate campaigns that used paste-to-Run and PowerShell/VBScript chains to deploy loaders and RATs (GeniexLoader and GeniexRAT were observed in one case). CTM360 has identified thousands of compromised sites hosting fake pages; attackers are even using blockchain-based EtherHiding to rotate lure hostnames on-chain without altering compromised sites directly. CloudSEK demonstrated another amplification vector: weaponizing invisible HTML/CSS tricks and prompt-overdose to make AI summarizers generate attacker-controlled ClickFix instructions for downstream distribution.
Why ClickFix works psychologically and operationally
ClickFix thrives because it blends social engineering with legitimate OS tooling. Users face CAPTCHA prompts, browser errors, and broken meetings regularly; a message asking them to âpaste this command to fix the issueâ fits into expected troubleshooting behavior. Unlike a suspicious executable attachment, a pasted command that invokes PowerShell or Run feels less obviously malicious. Tooling commoditizationâphishing kits, automation scripts, and prebuilt lure pagesâhas reduced attacker effort and increased campaign velocity. Finally, rapid infrastructure rotation and minimal local download signals help these campaigns evade traditional indicator-based defenses.
Detection and mitigation guidance
Microsoft recommends layered protections: cloud-delivered web filtering, network protections, application control, and PowerShell script-block logging. Detection efforts should go beyond download events to include hunting for suspicious browser cache activity, anomalies in RunMRU registry keys, wscript and PowerShell child processes, and unexpected scheduled tasks. Practical controls and user guidance include:
- Block or warn on attempts to paste commands into privileged utilities; educate users that CAPTCHAs or browser prompts should never request them to run code.
- Implement application control to restrict script hosts (wscript.exe, wmic, powershell.exe) from executing unapproved scripts.
- Enable PowerShell logging (script block logging) and forward logs to a central SIEM for real-time analysis.
- Harden web infrastructure and monitor for compromised sites (CTM360 reported thousands of active lure pages).
- Apply detection rules for processes that read browser profile folders and copy/rename cache artifacts to %LOCALAPPDATA%Temp.
- Treat long-lived or in-memory-only execution patterns as suspicious and investigate parent-child process trees tied to explorer, Run, or timeout.exeâlike binaries.
Conclusion
The use of browser cache smuggling to stage payloads demonstrates how attackers adapt existing features and user behaviors to overcome defensive constraints like the Run dialogâs length limit. ClickFix remains effective because it weaponizes trust in standard OS utilities and human willingness to âfixâ a problem. Organizations should combine user education with platform hardening, robust logging, and behavioral hunting focused on cache access patterns and script execution to interrupt these increasingly creative chains.
The Credential-Free Watchdog: Mastering Event-Driven App Automation
We have all been there. You are an automation lover. You haveâŚ
Face-Off: Windows PowerShell vs PowerShell Core â The Real-World Transition
PowerShell has come a long way since its inception, becoming an essentialâŚ
PowerShell in DevOps Workflows â GitHub Actions & CI/CD
PowerShellâs evolution from a Windows-centric scripting language to a cross-platform automation powerhouseâŚ
From The Blinking Cursor to The Thinking Machine: A Memoir of Automation
There is a specific kind of silence that only exists in aâŚ
Self-Hosted N8N on Affordable VPS: Practical Guide, Cost Comparisons, and Agentic AI Use Cases
Harnessing the power of self-hosted automation tools is transforming the way individualsâŚ
Ditching PsExec â Running Interactive SYSTEM Shells Natively in PowerShell
If youâve spent any time in Windows System Administration over the lastâŚ
Building an AI Coding Tool Stack for Modern Development
The past few years have quietly transformed how software is written. AI-assistedâŚ
When Local Trust Breaks: The OpenClaw 0-Click Vulnerability and What Developers Must Do Now
The speed at which developer-facing AI agents have been adopted is staggeringâŚ