ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
Key Points:
- A new ClickFix attack variant uses compromised websites to preload malicious scripts disguised as PNG files into browser caches, tricking victims into executing these cached payloads via copy-pasted commands.
- This method bypasses Windows Run dialog input length restrictions by staging a Visual Basic Script that executes further PowerShell scripts, ultimately delivering malware that targets browser and device credentials.
- ClickFix attacks exploit social engineering by prompting users to run attacker-supplied commands under the guise of troubleshooting fake errors, CAPTCHAs, or browser updates, leveraging trusted system tools like PowerShell and Windows Run.
- The attack ecosystem has evolved with automation kits and AI-based payload obfuscation techniques, leading to a surge in incidents, including nation-state campaigns by groups like Stardust Chollima and Sandworm targeting financial and government sectors.
- Microsoft and cybersecurity firms recommend enhanced detection strategies such as monitoring suspicious browser cache activity, script-block logging, and user education to avoid executing commands from untrusted prompts or CAPTCHAs.