Skip to content

Security2 publishers2 min readPublished Updated

ClickFix hides its payload in the browser cache before the victim pastes anything

Microsoft documented a ClickFix variant that stages its payload in the browser cache, keeping the command the victim pastes under Windows' 260-character Run limit. Detection moves to script engines reading browser profile folders, not the pasted text.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying ClickFix hides its payload in the browser cache before the victim pastes anything
Photo: thehackernews.com

What happened

  • The cached VBScript invokes cmd.exe to recursively enumerate files whose names start with f_ inside the browser profile folder, Firefox's in Microsoft's example path.
  • That script gathers host details through WMI, then fetches a PowerShell script named v.ps1 from cocojambo[.]us[.]com and launches it.
  • The chain ends by loading .NET assemblies into memory and injecting code into a freshly launched timeout.exe process to steal browser and device credentials.
  • Expel documented a cache-smuggling ClickFix chain in October 2025 that delivered a malware-laced ZIP, later identified as an Intrinsec red team engagement.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Caching the script conceals it and sidesteps the Run dialog's truncation, so a control that only inspects the pasted command string sees nothing worth blocking.
  • exposure The pasted command only runs content the browser already fetched, so by the time a user acts the payload is on disk with no inbound download at execution time.
  • precedent Phishing kits such as IUAM already automate Fix-type lures, so a working cache step is positioned to spread into commodity campaigns.

Choosing which cached file to run is the step Microsoft flagged as new. "It compares each file's byte length with an expected value," Microsoft explained. It then "copies a size-matching cache entry to %LOCALAPPDATA%\Temp\t.vbs, giving the cached payload a VBScript extension, then executes it with wscript.exe." [7] Older cache-smuggling variants searched the file contents for a marker string. This one keys on byte length. The expected size changes between variants. [7]

"Instead of downloading and executing remote payloads like the typical attack pattern," the Microsoft Threat Intelligence team said, "in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file." [2]

The loader that follows pulls a stage named cab.dat and runs its contents in a hidden window. [9] The injected process then fetches a secondary in-memory stage from capsysnet[.]vg and opens outbound connections to ciliabula[.]cc. [11]

ClickFix has been one of the most-used social engineering methods for about two years. It is popular because it turns the victim into the channel that runs the malware, and it draws both cybercriminals and nation-state crews. [13]

The cache step is one branch of how the technique is mutating. In August 2025, CloudSEK published a proof-of-concept aimed at AI summarizers in email clients, browser extensions and productivity platforms, showing they could be steered into delivering ransomware through ClickFix. [15] Attackers hide the instructions in HTML with zero-width characters, white-on-white text and off-screen positioning. The text is invisible to a reader but parsed by the model. They also repeat the payload dozens of times, in a method CloudSEK calls prompt overdose, so it dominates the context window. [16] "When such crafted content is indexed, shared, or emailed, any automated summarization process that ingests it will produce summaries containing attacker-controlled ClickFix instructions," CloudSEK said. [17]

What to watch

  • Whether Microsoft or others ship detection logic for cmd.exe and wscript.exe reading browser cache folders.
  • Whether off-the-shelf kits like IUAM adopt the cache-staging step seen in bespoke chains.
  • Follow-on reporting that ties cocojambo[.]us[.]com, capsysnet[.]vg and ciliabula[.]cc to a named operator.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories