ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache
ClickFix sites hide VBScript in the browser cache and trick users into running it.
Microsoft Threat Intelligence reported compromised websites that display a fake CAPTCHA or repair prompt and tell visitors to paste a command into the Windows Run dialog. The VBScript payload is already stored in the browser cache as a PNG-like resource; the command selects it by file size, copies it to a temporary script, and starts it with Windows Script Host. Later stages retrieve PowerShell, load code in memory, inject it into a legitimate process, and create a scheduled task to run a Python payload. The chain targets browser and device credentials. Microsoft named infrastructure including cocojambo[.]us[.]com, capsysnet[.]vg, and ciliabula[.]cc, but not the operators or a victim count.
- Victims are told to paste a command into the Windows Run box.
- VBScript is prefetched into the browser cache disguised as a PNG.
- Follow-on stages inject code and add a scheduled Python task.
- Microsoft published IoCs but no operator names or victim count.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | capsysnet.vg | the initial VBScript retrieves a PowerShell script. Domain capsysnet[.]vg Source of an additional memory-resident stage. Domain cil |
| domain | ciliabula.cc | [.]vg Source of an additional memory-resident stage. Domain ciliabula[.]cc Destination of outbound connections from the injected pro |
| domain | cocojambo.us.com | compromise (IoCs):- Type Indicator Description Domain/path cocojambo[.]us[.]com/alfa Location from which the initial VBScript retrieves |
Full article969 words · extracted from cybersecuritynews.com · click to collapse
A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter.
The instruction looks simple, but it makes the victim run the attacker’s command. The campaign is concerning because its main script is placed on the computer before that step, hiding in the browser cache rather than arriving as an obvious download.
Microsoft Threat Intelligence identified the activity in a cluster of compromised websites. Microsoft described in its published findings how attackers disguise the fetched script as a PNG file, allowing a shorter command to fit in Windows Run.
The public disclosure outlines a multistage attack targeting credentials. That design can weaken controls focused only on newly downloaded files and network requests at execution time.
It also continues a broader move toward human-led infection chains, seen in earlier browser cache smuggling reporting, where a routine-looking prompt becomes the first step toward credential theft and persistent access.
ClickFix Fake CAPTCHA Attack Executes Malware
The attack starts after a victim reaches an altered website. A fake verification or repair panel asks them to use Win+R, paste material from the clipboard, and run it.
A legitimate CAPTCHA keeps the verification inside the browser and never requires a person to execute a system command. Behind the page, the VBScript payload has already been stored in the browser profile cache as a PNG-like resource.
The pasted command opens a command processor to search cache files in locations such as the Firefox profile folder and compares their sizes with a value set by the attackers.
When it finds a match, the command copies the cached content into a temporary VBScript file and starts it through Windows Script Host.
Output and errors are suppressed, reducing signs that anything happened. The expected file size differs between variants, making a fixed size-based rule unreliable.
This split lets criminals avoid placing a long script directly in the Run box, while removing the need to fetch the main payload after the victim acts.
Earlier coverage of fake CAPTCHA phishing tactics shows why the model is effective: it abuses trust in security checks and shifts execution onto the user.
Microsoft Threat Intelligence has identified a cluster of compromised websites leading to ClickFix attacks. Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache… pic.twitter.com/DcbZQozZoI
— Microsoft Threat Intelligence (@MsftSecIntel) October 3, 2026
The VBScript gathers device information through Windows Management Instrumentation and retrieves a PowerShell script. Later activity downloads another payload, invokes .NET compilation tools, and starts a legitimate Windows utility. Subsequent code is loaded into memory and injected into that process to pursue browser-stored and device credentials.
Credential Theft
The campaign also tries to stay on the device. It changes the current user’s PowerShell setting to Bypass, unpacks Python components, and creates a scheduled task that launches a Python payload through a windowless interpreter.
These steps can give attackers a way back after the browser window is closed. Security teams should look beyond conventional download alerts.
Useful investigation points include browser-cache activity, the RunMRU registry key, unusual child processes from WScript or PowerShell, and new scheduled tasks.
Similar FileFix cache smuggling attacks demonstrate how hiding payloads in apparently harmless browser content can reduce visible network activity.
Microsoft recommends enabling cloud-delivered protection, web protection, network protection, application control, and PowerShell script-block logging.
Defenders should also investigate alerts for suspicious command execution and outbound connections, while users should close any page that asks them to paste commands into Run, Terminal, or PowerShell.
The main safeguard remains straightforward: CAPTCHA checks do not need command-line access. The campaign depends on visitors accepting instructions outside the browser, not simply viewing the page.
Recognizing that boundary can prevent the initial command from running, even when the payload is already cached. These findings describe a credential-focused intrusion chain, but Microsoft did not publish a victim count or identify the operators in this disclosure.
Cache staging does not mean the activity is invisible: suspicious script execution, process relationships, outbound connections, and persistence changes still provide opportunities for detection and investigation.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.