ClickFix Attack Hides VBScript Payload in Browser Cache
Microsoft says a ClickFix campaign cached a VBScript payload as an image, then tricked users into launching it.
Microsoft Threat Intelligence said a ClickFix cluster on compromised websites prefetched a VBScript payload into the browser cache, disguised as an image, before showing a fake CAPTCHA. Victims were told to open Run, paste a command, and press Enter; cmd.exe then matched cached files by name prefix and size, copied one as a .vbs file, and launched it with wscript.exe. The script collected host details via WMI, ran a PowerShell payload with execution policy bypassed, and injected further code into timeout.exe to steal browser and device credentials. Attackers later unpacked Python with tar.exe and created a scheduled task running pythonw.exe for persistence. Microsoft Defender blocks the activity as Trojan:Win32/ClickFix and Trojan:Win32/TermFix.
- Compromised sites prefetched a VBScript payload into the browser cache, disguised as an image.
- A fake CAPTCHA told victims to paste a Run command that located the cached file by size.
- The script used WMI, fetched PowerShell, and injected code into timeout.exe for credential theft.
- Persistence used tar.exe to unpack Python and a scheduled task running pythonw.exe.
- Defender detects the activity as Trojan:Win32/ClickFix and Trojan:Win32/TermFix.
Full article386 words · extracted from infosecurity-magazine.com · click to collapse
A ClickFix campaign has been observed hiding a VBScript payload in the browser cache, disguised as an image, so the script was already on the device when the victim was tricked into running a command through Windows Run.
Microsoft Threat Intelligence described the technique in a post on X on October 3, saying a cluster of compromised websites was leading visitors to the attacks.
ClickFix is a social engineering technique that gets victims to run attacker-supplied commands under the guise of a verification step. In this campaign, a fake CAPTCHA pop-up told users to open Run, paste from their clipboard and press Enter.
Rather than downloading the payload after the victim acted, the sites pre-fetched it into the browser cache. Microsoft said this helped hide the script and bypass the Run dialog's character limit, since the pasted command only had to find and launch a file already on disk.
Browser Cache Hides the Payload
The pasted command ran cmd.exe, which searched the browser profile folder for cached files whose names began with "f_" and compared each file's size with an expected value.
Rather than searching the cached content for a marker, as earlier attacks did, Microsoft said this one matched on size, copied the file to a temporary folder with a .vbs extension and ran it with wscript.exe.
The VBScript gathered host details through Windows Management Instrumentation (WMI), then fetched a PowerShell script and ran it with the execution policy bypassed. Later stages compiled and loaded further code in memory, injecting it into the legitimate timeout.exe process for credential theft against browsers and devices.
Read more on ClickFix: ClickFix Now Cybercriminals' Favorite Malware Delivery Technique
Persistence Through a Scheduled Task
The malware then connected to attacker servers, unpacked a copy of Python using the built-in tar.exe and created a scheduled task that ran a Python payload through pythonw.exe, giving the attackers a foothold that survived a reboot.
Microsoft Defender Antivirus blocks malicious command execution as Trojan:Win32/ClickFix and Trojan:Win32/TermFix. Microsoft also recommended turning on cloud-delivered protection, network protection, application control and PowerShell script-block logging.
For hunting, it advised looking beyond download events to browser activity, unusual WScript, PowerShell and scheduled-task activity and the RunMRU registry key, which records what users type into the Run box. A CAPTCHA should not ask users to run code, Microsoft added.