Microsoft Threat Intelligence has detailed a new ClickFix attack in which compromised websites pre-fetch a malicious script into the browser cache, disguised as a PNG file. Instead of downloading a remote payload at execution time, the victim is tricked into pasting a command into the Windows Run dialog that runs the cached website content already present on the device. This browser cache smuggling approach also lets attackers conceal the payload and bypass the roughly 260-character limit that Windows Run imposes on input.

The staged payload is a Visual Basic Script that searches the browser profile folder for files whose names start with f_, compares each file's byte length to an expected value, and copies a matching cache entry to %LOCALAPPDATA%\Temp\t.vbs before executing it with wscript.exe. The script then gathers host information via Windows Management Instrumentation, fetches a PowerShell script from an external server, and downloads an intermediate payload. Ultimately, .NET assemblies are loaded into memory and injected into a legitimate Windows process (timeout.exe) to steal browser and device credentials.

This is not the first time cache smuggling has been used in ClickFix attacks; Expel documented a similar chain in October 2025, later attributed to a red team engagement. The broader ClickFix ecosystem has expanded rapidly, with phishing kits like IUAM automating campaign creation and CrowdStrike reporting a 563% increase in fake CAPTCHA lures in 2025. Separately, CloudSEK demonstrated how AI summarization tools could be manipulated with invisible prompt injection to produce attacker-controlled ClickFix instructions, highlighting the technique's growing reach.