Back to Newsroom
Threat Intel

ClickFix Attackers Now Smuggle Malware Through Your Browser's Cache

A new ClickFix variant pre-loads a malicious file into the victim's own browser cache, then uses a short Windows Run command to find and launch it — dodging the dialog's character limit and leaving no download for defenders to catch.

ClickFix Attackers Now Smuggle Malware Through Your Browser's Cache

A newly observed variant of the ClickFix social-engineering attack hides its malicious payload inside the victim's own browser cache, letting attackers slip past the character limits Windows imposes on commands typed into the Run dialog.

What happened

Microsoft's threat intelligence team has documented a ClickFix campaign that pre-loads a booby-trapped file — disguised as a harmless PNG image — into a compromised website's visitor browser cache before the attack even begins. When the victim is later talked into pasting a short command into the Windows Run box, that command doesn't download anything; it simply scans the browser's cache folders, finds the planted file by matching its exact byte size, copies it out as an executable, and runs it.

Because Run truncates anything beyond roughly 260 characters, earlier ClickFix variants struggled to fit a full download-and-execute command into the box. By pre-staging the payload locally and triggering it with a short lookup command, attackers sidestep that limit entirely — and the activity looks less like a download and more like routine file access.

Once running, the script profiles the device over Windows Management Instrumentation, retrieves a PowerShell loader from attacker infrastructure, and uses it to pull down and execute a further encrypted stage entirely in memory. The chain finishes by launching a renamed, legitimate-looking Windows process that reaches out to attacker-controlled infrastructure and is positioned to harvest credentials.

Microsoft says this is the first confirmed use of browser-cache smuggling inside a live ClickFix attack; a similar caching technique surfaced in a red-team exercise in October 2025 but hadn't previously appeared in the wild.

Why it matters

ClickFix has become one of the most effective infection techniques of the last two years precisely because it turns the victim into the attacker: rather than deliver a suspicious file, the lure — a fake CAPTCHA, browser-update prompt, or error message — talks the user into copying and running a command themselves, using tools like Run, PowerShell, or Terminal that organizations already trust. CrowdStrike has tracked a 563% rise in fake-CAPTCHA ClickFix lures over the past year, and the technique is no longer limited to cybercriminals: nation-state groups including Russia's Sandworm and North Korea's Stardust Chollima (BlueNoroff) have both been linked to ClickFix campaigns against targeted employees.

Cache smuggling raises the bar further for defenders. Because the payload is already sitting on disk inside a legitimate browser folder before the Run command ever executes, there's no separate download event for security tools to flag — the signal shifts from "what got downloaded" to "what accessed the cache and what ran next."

What to do

  • Treat any prompt that asks you to copy and paste a command into Run, PowerShell, or Terminal as a red flag — legitimate CAPTCHAs and browser updates never require this.
  • Enable PowerShell script block logging and monitor for PowerShell or WScript processes spawned from browser or Explorer activity.
  • Watch the Windows RunMRU registry key and scheduled-task creation for anomalies, not just download logs.
  • Apply web and network protection, plus application control, to catch the loader and second-stage payload even if the initial cache-based trigger is missed.
  • Reinforce user training: a "fix" that requires running a command is the attack, not the solution.
SHARE