Microsoft Threat Intelligence detailed a ClickFix variant that pre-fetches malicious scripts into the browser cache, disguised as PNG files, so victims run content already stored locally rather than downloading a remote payload when they paste the attacker's command. The approach conceals the payload and sidesteps the roughly 260-character limit of the Windows Run dialog. The chain uses VBScript to enumerate browser cache files, pulls PowerShell from external servers, and injects .NET assemblies into legitimate processes such as timeout.exe to steal browser and device credentials before fetching further in-memory stages. The cache enumeration specifically references Firefox, and similar tricks have targeted macOS Terminal users.