Microsoft Details ClickFix Attacks Caching VBScript Payloads
Microsoft says ClickFix sites cache VBScript as an image and trick users into running it from Windows Run to steal credentials.
Microsoft Threat Intelligence reported a ClickFix cluster on compromised websites that displays a fake CAPTCHA or repair prompt and tells visitors to paste a command into the Windows Run dialog. The outlets agree a VBScript payload is already in the browser cache—called a PNG or PNG-like resource by Cyber Security News and The Hacker News, and an image by Infosecurity Magazine—then selected and launched so later stages can steal browser and device credentials. The Hacker News says this bypasses the Run dialog's roughly 260-character limit by matching a sized Firefox cache entry and starting it with wscript.exe, while Infosecurity Magazine says cmd.exe matches files by name prefix and size, collects host details via WMI, and runs PowerShell with execution policy bypassed. On injection, The Hacker News and Infosecurity name timeout.exe, whereas Cyber Security News says only a legitimate process. Cyber Security News and Infosecurity describe a scheduled Python task, with Infosecurity adding that attackers unpack Python using tar.exe and run pythonw.exe; The Hacker News does not mention Python. Microsoft listed cocojambo[.]us[.]com, capsysnet[.]vg, and ciliabula[.]cc but no operators or victim count, Defender flags Trojan:Win32/ClickFix and Trojan:Win32/TermFix, and The Hacker News also cites a 563% rise in fake-CAPTCHA incidents in 2025 plus a 2025 CloudSEK proof of concept that hid ClickFix steps in AI summaries.
- Microsoft Threat Intelligence reported compromised sites that show a fake CAPTCHA or repair prompt and tell visitors to paste a command into the Windows Run dialog.
- A VBScript payload is prefetched into the browser cache, described as a PNG or PNG-like file by two outlets and as an image by Infosecurity Magazine, then copied out and started with wscript.exe or Windows Script Host.
- The Hacker News says the cached payload bypasses the Run dialog's roughly 260-character limit and that the script matches a sized Firefox cache entry; Infosecurity Magazine says cmd.exe matches by name prefix and size.
- Later stages collect host details via WMI, run PowerShell (with execution policy bypassed, per Infosecurity), inject code, and steal browser and device credentials; injection is into timeout.exe according to The Hacker News and…
- Cyber Security News and Infosecurity Magazine report a scheduled task running a Python payload; Infosecurity specifies unpacking Python with tar.exe and running pythonw.exe, which The Hacker News does not mention.
- Microsoft published infrastructure including cocojambo[.]us[.]com, capsysnet[.]vg, and ciliabula[.]cc, but no operator names or victim count; Defender detects Trojan:Win32/ClickFix and Trojan:Win32/TermFix.
- The Hacker News notes earlier cache-smuggling research, a 2025 CloudSEK proof of concept that hid ClickFix steps in AI summaries, and CrowdStrike's finding that fake-CAPTCHA incidents rose 563% in 2025.
Coverage timelineoldest first · each row is one article
- · 3d agoClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache
Cyber Security News· 71
ClickFix sites hide VBScript in the browser cache and trick users into running it.
- · 2d agoClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
The Hacker News· 64
Microsoft says ClickFix attacks now smuggle VBScript through the browser cache to bypass Windows Run limits.
- · 2d agoClickFix Attack Hides VBScript Payload in Browser Cache
Infosecurity Magazine· 62