
ClickFix Uses Browser Cache to Bypass Windows Run Limits
Microsoft describes a ClickFix variant that hides a VBScript payload in browser cache to evade the Windows Run dialog's character cap before stealing credential…
A newly observed ClickFix attack chain is using compromised websites to stash a malicious script inside the web browser's cache, then tricking the victim into running it directly from that cache, according to Microsoft Threat Intelligence. The technique is notable because it hides the final payload as a PNG file and works around a hard limit in the Windows Run dialog, which cuts off commands longer than roughly 260 characters.
In a typical ClickFix attack, a user is shown a fake error, CAPTCHA, or browser update and told to copy a command and paste it into a trusted Windows utility such as the Run dialog, PowerShell, or Terminal. Microsoft says that in this new variant the websites pre-fetch a script payload and place it into the browser cache disguised as a PNG image. When the victim later pastes and runs the attacker-supplied command, that command does not download the remote script; instead it executes the cached website content that is already sitting on the device.
Microsoft's description of the chain is specific. The staged payload is a Visual Basic Script, or VBScript, a built-in Windows scripting language. The script calls the command prompt, cmd.exe, and recursively lists files in the browser's profile folder, for example under %LOCALAPPDATA%\Mozilla\Firefox\Profiles, looking for file names that begin with f_. Instead of searching for a marker inside the file contents, as earlier campaigns did, this version compares each file's byte length to an expected value. When it finds a cache entry of the right size, it copies that file to %LOCALAPPDATA%\Temp\t.vbs, giving the cached payload a .vbs extension, and then runs it with wscript.exe. Any output or error messages from the copy are suppressed, and the expected size changes across different variants.
From there the VBScript collects basic information about the computer through Windows Management Instrumentation, or WMI, a service that lets programs query system details. It then fetches a PowerShell script named v.ps1 from an external server at cocojambo[.]us[.]com/alfa and launches it. That PowerShell script acts as a conduit for an intermediate PowerShell payload, which downloads a next stage called cab.dat from another location. When cab.dat is downloaded, its contents are read and executed in a hidden window. The chain eventually loads .NET assemblies into memory and injects code into a newly launched legitimate Windows process, timeout.exe, with the goal of stealing credentials stored in browsers and on the device. The injected process also launches PowerShell to retrieve a secondary in-memory stage from capsysnet[.]vg and makes outbound connections to ciliabula[.]cc.
Microsoft first shared details of this cache smuggling method in a post on X. It is not the first time attackers have staged payloads in the browser cache as part of a ClickFix campaign. In October 2025, Expel documented an attack chain that used cache smuggling to deliver a malware-laced ZIP archive. That activity was later identified as a red team engagement carried out by Intrinsec, meaning it was a simulated exercise rather than a criminal campaign.
ClickFix itself is a social engineering technique that has grown rapidly over the past two years because it turns the victim into the delivery mechanism. Instead of breaking into a computer directly, the attacker persuades the user to run the malicious command personally, which is often enough to bypass security controls that focus on files and executables. CrowdStrike reports that incidents involving fake CAPTCHA lures increased by 563 percent in 2025. The technique is effective because it uses the familiar language of troubleshooting. Employees routinely deal with broken meetings, authentication challenges, CAPTCHA prompts, browser errors, and application issues, so a quick fix request can feel less suspicious than an unexpected email attachment. Bob Erdman, associate vice president of research and development at Fortra, explained that ClickFix combines psychological manipulation with the abuse of legitimate operating-system tools, and the dangerous part is that the victim executes the command themselves, effectively opening the door.
The attack also relies on standard tools that users trust, such as PowerShell, Windows Run, and Terminal on macOS, rather than asking them to download an unfamiliar program. The usual chain is predictable. Victims are led to a fake or compromised website through phishing emails or malvertising. That site shows a fake error, CAPTCHA, or browser update. It then provides a solution and tells the user to copy a command. Some variants use JavaScript to automatically place the command into the clipboard. Finally, the user is asked to paste the command into Run, PowerShell, Windows Terminal, macOS Terminal, or another trusted system utility, which retrieves additional payloads and leads to malware deployment.
Campaigns have also become commoditized. Phishing kits such as IUAM can automate the creation of Fix-type attacks, lowering the barrier to entry and accelerating frequency. In August 2025, CloudSEK released a proof-of-concept showing how artificial intelligence summarization systems in email clients, browser extensions, and productivity platforms can be weaponized for ClickFix. The payloads are hidden in HTML with CSS tricks such as zero-width characters, white-on-white text, and off-screen positioning. A human cannot see them, but an AI summarizer can parse them. The attacker then uses a method called prompt overdose, repeating the payload dozens of times so it dominates the model's context window and steers the generated summary to include attacker-controlled ClickFix instructions. CloudSEK observed that prompt overdose combined with invisible injection can override legitimate context inside summarizers.
Website owners are also caught in the middle. CTM360 reports that threat actors have been exploiting known vulnerabilities in WordPress plugins, including CVE-2026-6854, to take control of websites and inject ClickFix lures. The injected script uses a technique called EtherHiding, which stores the active lure hostname in blockchain data. That lets attackers rotate infrastructure by making on-chain updates without modifying the compromised site. CTM360 identified more than 3,000 actively compromised websites hosting fake pages, with attack chains leading to Vidar Stealer. ReversingLabs said in a July 2026 report that ClickFix presents fewer malware signals of the sort traditional defenses are calibrated to detect, and campaigns play out quickly with shifting infrastructure intended to evade detection based on historic indicators.
State-aligned groups have also adopted the method. CrowdStrike observed the North Korea-aligned Stardust Chollima cluster, also known as BlueNoroff, likely targeting an employee at a financial services organization in July 2026 through a bogus video conferencing site. The employee encountered a fake technical issue and a fix that
How to Protect Yourself
- Never paste a command from a website, pop-up, or CAPTCHA into the Run box, Terminal, or PowerShell. A real verification prompt will never ask you to run code.
- If a page tells you to copy and paste a fix to solve an error or update, close the page and get help from your IT team or the site's official support channel instead.
- Keep your web browser and operating system updated so built-in protections are current.
- If you manage a website, install WordPress and plugin updates as soon as they become available, and remove plugins you do not use.
- Turn on two-factor authentication for important accounts, because this attack can steal saved browser and device credentials.
Vulnerabilities & Fixes
- CVE-2026-6854 CVE-2026-6854 is a known vulnerability in WordPress plugins that threat actors have exploited to take over sites and inject ClickFix lures; patching affected plugins mitigates it. View the fix & details →
Terms Explained
- ClickFix A social engineering lure that asks users to copy and paste a command to fix a fake problem.
- browser cache Temporary storage on your computer where websites keep images or scripts so pages load faster.
- Windows Run dialog A small box opened with the Windows key and R that runs commands, but limits long input.
- VBScript A scripting language built into Windows that can run commands on a computer.
- PowerShell A powerful command tool in Windows used for administration, often abused by attackers.
- WMI Windows Management Instrumentation, a Windows service that allows programs to gather system information and manage the device.
- prompt injection A technique that hides instructions in content so an AI system reads and follows them while a human cannot see them.
- EtherHiding A method that hides attacker-controlled web addresses in blockchain data so compromised websites can fetch them without editing the site.