ClickFix now hides its payload in the browser cache to slip past download defenses
Microsoft Threat Intelligence says fake CAPTCHA pages now pre-load a script into the browser cache disguised as a PNG, sidestepping both download monitoring and the Windows Run dialog's character limit.
At a glance
- The Hacker News reports Microsoft Threat Intelligence found ClickFix pages pre-fetching a script payload into the browser cache disguised as a PNG file.
- The trick works around the roughly 260-character truncation in the Windows Run dialog, so no remote download happens at execution time.
- More than 3,000 compromised websites were found hosting the fake pages, with chains ending in Vidar Stealer.
- CrowdStrike tied the same lure style to North Korea-aligned Stardust Chollima and Russia's Sandworm.
A new variant of the ClickFix social engineering attack stashes its payload in the victim's own browser cache before the victim ever runs a command, according to Microsoft Threat Intelligence research reported by The Hacker News on 6 October 2026. The change is significant for defenders because the decisive download happens while the user is merely browsing, not at the moment the malicious command executes — which is where most download-focused controls are watching.
What happened
ClickFix is the family of lures that shows a visitor a fake CAPTCHA, verification screen or update prompt and talks them into pasting a prepared command into the Windows Run dialog. In the variant Microsoft describes, the page does the staging work in advance. As Microsoft put it, "instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file."
The Hacker News notes the underlying cache-smuggling idea was documented by Expel in October 2025, with that earlier activity later attributed to Intrinsec as a red team engagement. What is new is its adoption in live criminal and state-linked campaigns at scale.
Technical details
The approach also solves a practical problem for the attackers. The Windows Run dialog truncates input at roughly 260 characters, which limits how much a lure can get a user to paste in one go. By pre-caching the payload, the pasted command only has to locate what is already on disk.
Per the reporting, the staged component is a Visual Basic Script that walks browser profile folders looking for cache entries with f_ prefixes, matches them by byte length rather than by content markers, copies the match to %LOCALAPPDATA%\Temp\t.vbs and runs it through wscript.exe. From there the chain moves through PowerShell, an intermediate v.ps1 stage, a cab.dat file and .NET assemblies injected into legitimate Windows processes such as timeout.exe, before harvesting browser and device credentials. Reported command-and-control domains include cocojambo[.]us[.]com, capsysnet[.]vg and ciliabula[.]cc, with attack chains ending in Vidar Stealer. Microsoft identified more than 3,000 compromised websites hosting the fake pages.
Who is affected
The lure is indiscriminate, but the same playbook is in state-linked hands. CrowdStrike observed North Korea-aligned Stardust Chollima targeting a financial services employee in July 2026 through fake video conferencing sites, delivering two previously undocumented families, GeniexLoader and GeniexRAT. Russia's Sandworm used ClickFix against suspected Ukrainian employees via compromised Ukrainian websites. CrowdStrike also recorded a 563 percent rise in fake CAPTCHA lure incidents across 2025. ReversingLabs summarised the defensive problem bluntly: "ClickFix presents fewer malware signals of the sort that traditional defenses are calibrated to detect."
What to do
Microsoft's recommendations are cloud-delivered, web and network protection, application control, and PowerShell script-block logging. For hunting, it points to suspicious browser activity, RunMRU registry keys, WScript and PowerShell processes spawned as children of a browser, and newly created scheduled tasks. Because the payload arrives as a cached file, teams should also treat script interpreters launching shortly after browsing as a signal in its own right rather than relying on download telemetry. The user-facing message is the simplest control available: a CAPTCHA should never ask anyone to run a command.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



