ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X. Thus, when the victim is prompted to paste and execute a malicious command -- as is the case with ClickFix attacks – it executes the cached website content that's already on the device. What's notable about this browser cache smuggling approach is that it allows the attackers to conceal the payload script and bypass the character limit restrictions . The Windows Run dialog, triggered by Win + R, truncates any input that exceeds approximately 260 characters. In the attack chain observed by Microsoft, the staged payload is a Visual Basic Script (VBScript), which th...
Oct 06, 2026