A new variant of the ClickFix social engineering technique is leveraging browser cache to smuggle malicious payloads past Windows security controls, according to a report from Microsoft Threat Intelligence. The attack, detailed in a post on X, marks a shift from traditional ClickFix tactics that rely on downloading remote executables. Instead, compromised websites pre-load a script into the browser's cache disguised as a PNG image, then trick users into executing it locally.
How the Attack Works
ClickFix attacks typically present victims with fake error messages or CAPTCHA prompts that instruct them to paste a command into the Windows Run dialog (Win+R). That command usually downloads and executes a remote payload. The new variant, however, avoids the download step entirely. According to Microsoft's Threat Intelligence team, the compromised site uses a technique to fetch a malicious script and store it in the browser cache under the guise of a PNG file. When the user follows the ClickFix instructions, the command they paste into the Run dialog retrieves the script directly from the local cache, bypassing network-based detection and Windows' execution limits.
This cache-based delivery is significant because it sidesteps common security measures that monitor outbound network traffic or block execution of files from remote locations. By keeping the payload local, the attack reduces its footprint and makes it harder for traditional endpoint detection to flag the activity.
Why This Matters
The ClickFix technique has gained popularity among threat actors because it exploits user trust and basic system functionality rather than software vulnerabilities. The browser cache variant adds a layer of stealth. Because the payload is stored as an image file, it may evade content filters that scan for executable downloads. Additionally, the use of the Run dialog means the attack does not require macros, exploits, or elevated privileges—just a user willing to follow instructions.
Microsoft's report highlights that this method can bypass Windows' Run limits, which typically restrict the length of commands or block certain characters. By referencing a cached file, the command can be shorter and less suspicious, increasing the likelihood of success.
Defensive Recommendations
Organizations should reinforce user awareness training to recognize ClickFix lures, which often impersonate legitimate software updates or security checks. Technical controls can also help:
- Browser cache management: Consider policies that clear cache on exit or restrict cache storage for untrusted sites.
- Application control: Use Windows Defender Application Control (WDAC) or AppLocker to prevent execution of scripts from unusual locations, including browser cache directories.
- Network monitoring: While the payload is local, the initial fetch of the fake PNG still generates network traffic. Detect anomalous requests for image files that are later executed.
- Endpoint detection: Monitor for processes that load scripts from browser cache paths, especially when triggered by Run dialog commands.
Microsoft has not attributed this specific campaign to a particular threat actor, but ClickFix has been used by both cybercriminals and state-sponsored groups in recent months.
Conclusion
The evolution of ClickFix to abuse browser cache demonstrates how attackers continue to refine social engineering tactics to evade detection. As defenders bolster network and endpoint controls, adversaries are finding creative ways to keep payloads local and low-profile. Staying informed about these shifts is critical for security teams. For the full technical details, refer to Microsoft's post on X and the original coverage by The Hacker News.
Source: The Hacker News