ClickFix Attack Smuggles Malicious Payloads via Browser Cache to Bypass Windows Run Limits

A new variant of the ClickFix social engineering technique is leveraging browser cache to deliver malicious payloads while evading Windows Run dialog restrictions, according to Microsoft Threat Intelligence. The attack, reported on October 6, 2026, by The Hacker News, represents a notable evolution in how threat actors bypass traditional detection and execution limits.

How the Attack Works

The ClickFix technique has long relied on deceiving users into pasting and executing malicious commands, often through fake CAPTCHA prompts or error messages. In this new variant, compromised websites are used to pre-fetch a script payload into the browser's cache. This payload is disguised as a PNG image file, making it less likely to raise suspicion during network inspection.

Instead of downloading and executing a remote payload—the typical pattern—the attack uses the cached file directly. When the user follows the attacker's instructions (e.g., pasting a command into the Run dialog), the command retrieves the cached script from the browser's cache directory and executes it. Because the payload is already on the system, the attack can bypass Windows Run dialog limits, such as the maximum command length or restrictions on remote execution.

Microsoft Threat Intelligence disclosed the technique in a post on X, stating: "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file."

Bypassing Windows Run Limits

The Windows Run dialog has a character limit and typically blocks direct execution of remote scripts. By caching the payload locally, attackers avoid these constraints. The Run command only needs to reference the local cache path, which is shorter and appears benign. This also helps evade network-based detection, as the payload is fetched during normal browsing activity and stored as an image file.

Implications for Defenders

This attack highlights the growing sophistication of ClickFix campaigns. Defenders should consider:

  • Monitoring browser cache directories for unusual file types or script content.
  • Restricting user execution privileges to prevent unauthorized script execution.
  • Educating users about social engineering tactics that prompt them to paste commands into Run dialogs.
  • Implementing application whitelisting to block unauthorized executables.

Microsoft's disclosure underscores the need for layered defenses that account for both network and endpoint behaviors. As attackers continue to innovate, staying informed about emerging techniques is critical.

Conclusion

The ClickFix attack using browser cache is a reminder that social engineering remains a powerful vector. By combining user deception with technical evasion, attackers can bypass common security controls. Organizations should review their detection and response strategies to address this evolving threat.

For more details, refer to the original report by The Hacker News: ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits.