ClickFix Attack Abuses Browser Cache to Bypass Windows Run Limits
A new variant of the ClickFix social engineering technique is leveraging browser cache to smuggle malicious payloads onto Windows systems, according to a report from Microsoft Threat Intelligence. The attack, first highlighted in a post on X, marks a shift from the typical ClickFix playbook by avoiding direct remote downloads that often trigger security alerts.
How the Attack Works
In a traditional ClickFix attack, a compromised or malicious website displays a fake error message or CAPTCHA, instructing the visitor to copy and paste a command into the Windows Run dialog (or PowerShell) to "fix" the issue. That command typically downloads and executes a remote payload, such as an infostealer or loader.
The new variant, however, pre-fetches the payload into the browser cache before the user ever interacts with the lure. According to Microsoft, the compromised websites "pre-fetch a script payload into the browser cache disguised as a PNG file." When the victim follows the ClickFix instructions, the command executed via the Run dialog retrieves the payload from the local browser cache rather than from a remote server.
Why This Matters
By sourcing the payload locally, the attackers sidestep several common detection and prevention mechanisms:
- No outbound network request: Security tools that monitor for suspicious downloads or command-and-control (C2) traffic may not flag the activity because the payload never traverses the network at execution time.
- Bypassing Windows Run limits: The Run dialog has character limits that can restrict the length of commands. By using a short command to extract the cached file, attackers can deliver larger payloads than would otherwise fit.
- Evading reputation checks: The payload is disguised as a PNG image, which may bypass file type restrictions or content filters that block executable downloads.
- Reduced forensic artifacts: Traditional network logs may not capture the payload retrieval, complicating incident response.
The Broader ClickFix Trend
ClickFix has become a prevalent initial access technique throughout 2025 and 2026, used by a wide range of threat actors, from financially motivated cybercriminals to state-sponsored groups. Its success relies on convincing users to execute commands themselves, effectively turning the victim into the infection vector. Microsoft's disclosure underscores how attackers continue to refine the method to evade modern defenses.
Mitigation and Detection
Microsoft and other security researchers recommend a defense-in-depth approach:
- User awareness: Educate users about ClickFix lures, particularly fake error messages that instruct them to run commands. Legitimate websites never ask users to paste code into the Run dialog.
- Application control: Implement policies that restrict execution of scripts and binaries from unusual locations, including browser cache directories.
- Browser hardening: Configure browsers to limit cache storage or clear cache on exit for high-risk users. Some enterprise browsers offer additional controls.
- Endpoint detection and response (EDR): Monitor for processes that read from browser cache paths or execute files with image extensions. Behavioral rules can flag such anomalies.
- Network monitoring: While the payload retrieval is local, the initial pre-fetch still generates network traffic. Detect unusual requests for PNG files that are actually scripts.
Conclusion
The ClickFix cache-smuggling technique is a reminder that attackers are constantly innovating to bypass layered defenses. Organizations should review their detection coverage for local file execution and reinforce user education around social engineering. As Microsoft's report shows, even well-known attack patterns can be adapted in novel ways to exploit trust in everyday tools like the browser cache and the Windows Run dialog.
For the full technical details, refer to the original report from The Hacker News.