Full Report
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.
Analysis Summary
# Tool/Technique: ClickFix (Browser Cache Smuggling Variant)
## Overview
ClickFix is a social engineering technique that tricks users into copying and pasting a malicious command into a Windows Run dialog or terminal, under the guise of "fixing" a browser error. The latest variant utilizes "Browser Cache Smuggling," where the payload is pre-fetched into the browser's local cache as a disguised file (e.g., a PNG) to bypass Windows character limits and network security filters that inspect active downloads.
## Technical Details
- **Type:** Technique / Social Engineering / Malware Loader
- **Platform:** Windows (via web browsers such as Firefox, Chrome, etc.)
- **Capabilities:** Bypasses Windows Run (Win+R) character limits (approx. 260 chars), evades traditional download detections, executes in-memory payloads, and harvests credentials.
- **First Seen:** Variant documented Oct 2026 (Cache smuggling concepts seen as early as Oct 2025).
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566 - Phishing (Social Engineering)
- T1189 - Drive-by Compromise
- **TA0002 - Execution**
- T1059.003 - Command and Scripting Interpreter: Windows Command Shell
- T1059.005 - Command and Scripting Interpreter: VisualBasic
- T1204.002 - User Execution: Malicious File
- **TA0005 - Defense Evasion**
- T1027.006 - Obfuscation/HTML Smuggling
- T1055 - Process Injection
- T1140 - Deobfuscate/Decode Files or Information
- **TA0006 - Credential Access**
- T1555 - Credentials from Password Stores
## Functionality
### Core Capabilities
- **Browser Cache Smuggling:** Pre-fetches a script disguised as an image (PNG) into the browser’s local cache folder.
- **Bypassing Input Limits:** By referencing a local cached file, the attacker avoids the character limits of the Windows Run dialog that would otherwise prevent long obfuscated scripts from being pasted.
- **File Enumeration:** Uses VBScript to recursively search browser profile directories (e.g., `%LOCALAPPDATA%\Mozilla\Firefox\Profiles`) for files starting with `f_` that match specific byte sizes.
- **Payload Reconstitution:** Copies the identified cache file to the Temp directory with a `.vbs` extension and executes it via `wscript.exe`.
### Advanced Features
- **Fileless Execution:** Paves the way for .NET assemblies that are loaded directly into memory.
- **Process Injection:** Injects malicious code into legitimate Windows processes (specifically `timeout.exe`) to evade detection.
- **Multi-Stage Loading:** Utilizes a chain of VBScript -> PowerShell -> .NET to gradually escalate privileges and establish persistence.
## Indicators of Compromise
- **File Names:**
- `t.vbs` (Temporary script in `%LOCALAPPDATA%\Temp\`)
- `v.ps1` (Staging PowerShell script)
- `cab.dat` (Intermediate payload)
- **Network Indicators:**
- `cocojambo[.]us[.]com`
- `capsysnet[.]vg`
- `ciliabula[.]cc`
- **Behavioral Indicators:**
- `wscript.exe` executing files from the `%TEMP%` directory.
- `cmd.exe` or PowerShell recursively searching browser profile folders.
- Unexpected outbound connections from `timeout.exe`.
## Associated Threat Actors
- Cybercriminal groups (unnamed in article)
- Nation-state actors (general association)
- Intrinsec (Previous red team engagement documented in 2025)
## Detection Methods
- **Behavioral Detection:**
- Monitor for the `Win+R` dialog being followed by commands that invoke `cmd.exe` to search browser cache directories.
- Alert on `wscript.exe` or `cscript.exe` launching scripts named `t.vbs` or other single-character files in the Temp folder.
- **Endpoint Monitoring:** Detect process injection into `timeout.exe` or other short-lived system utilities.
- **Network Detection:** Block and alert on traffic to the identified malicious domains (e.g., `ciliabula[.]cc`).
## Mitigation Strategies
- **User Education:** Train users never to copy and paste commands from websites into the Windows Run dialog or PowerShell.
- **Attack Surface Reduction:** Restrict the execution of VBScript (`.vbs`) and other potentially dangerous script extensions via AppLocker or Windows Defender Application Control (WDAC).
- **Hardening:** Disable or restrict the Windows Run dialog in high-risk environments via Group Policy.
## Related Tools/Techniques
- **HTML Smuggling:** The underlying concept used to bypass perimeter defenses.
- **FileFix / ConsentFix:** Related social engineering "Fix-type" attacks.
- **ClearFake:** Another social engineering framework often associated with ClickFix patterns.