ClickFix attacks use browser cache to smuggle payloads
A recent ClickFix campaign is hiding malicious Visual Basic scripts disguised as image files in browser caches on victims' devices, according to Microsoft Threat Intelligence. Instead of downloading malware after tricking users into running a command, attackers now pre-load the payload into the browser cache. This method helps circumvent character limits in the Windows Run dialog and hides the script until execution. The VBScript ultimately enables theft of credentials and creates a persistent backdoor.
- Payload placed in cache as PNG, not downloaded later
- Run dialog command executes cached malware already on device
- VBScript gathers host info, runs further PowerShell scripts
- Attack persists via scheduled task using unpacked Python
- Microsoft recommends enhanced antivirus and logging settings
Sources covering this
In this story
More in Cybersecurity
Hackers send extortion message through ASOS app
Hackers took control of ASOS's app notification system and sent a message to users claiming to have breached the company's Snowflake…
Phishing campaign uses fake AI ad tools to steal credentials
Researchers report a phishing operation targeting digital advertising professionals through counterfeit AI tools like ChatGPT, Gemini,…
Nikkei reveals breaches of employee email accounts
Japanese media group Nikkei disclosed that two employee cloud email accounts were breached in separate incidents this year.
Oracle Health breach exposed data of nearly 20 million
A cyberattack on Oracle Health in early 2025 exposed sensitive data belonging to nearly 20 million people, according to the Texas…