Last updated: October 7, 2026 at 2:03 PM UTC
All 903 Vulnerability 367 Breach 144 Threat 385 Defense 7
Tag: browser-cache (1 article)Clear

ClickFix campaign smuggles payloads through browser cache to bypass Windows Run character limits

Microsoft Threat Intelligence detailed a ClickFix variant that pre-fetches malicious scripts into the browser cache, disguised as PNG files, so victims run content already stored locally rather than downloading a remote payload when they paste the attacker's command. The approach conceals the payload and sidesteps the roughly 260-character limit of the Windows Run dialog. The chain uses VBScript to enumerate browser cache files, pulls PowerShell from external servers, and injects .NET assemblies into legitimate processes such as timeout.exe to steal browser and device credentials before fetching further in-memory stages. The cache enumeration specifically references Firefox, and similar tricks have targeted macOS Terminal users.

Check
Train users against pasting commands from websites into the Run dialog or a terminal, and monitor endpoints for VBScript cache enumeration and injection into processes like timeout.exe.
Affected
Windows users tricked by a ClickFix lure run a payload pre-loaded into the browser cache, bypassing Run dialog limits to launch PowerShell and steal credentials.
Fix
Block the ClickFix workflow with user training, restrict Run dialog and script host usage, inspect browser cache abuse, and alert on .NET injection into benign binaries.