Security News

Microsoft Warns of ClickFix Attack That Hides Malware in Your Browser Cache

iTnews · 6 Oct 2026
Key Takeaway Train staff never to paste commands into the Windows Run dialog because a website asks them to, and make sure your security tools monitor script activity and scheduled tasks, not just file downloads.

Microsoft Threat Intelligence has described a new twist on ClickFix, a scam that talks people into running malicious commands themselves. In the campaign, compromised websites quietly loaded a script into visitors' browser caches, disguised as a PNG image. The lure posed as a Cloudflare human verification check, telling users to open the Windows Run dialog, paste the clipboard contents and press Enter. By then, the payload was "already on the device, loaded, and ready to be executed," Microsoft said.

The technique builds on "cache smuggling", described by researcher Marcus Hutchins of Expel in October 2025, which avoids a conventional file download at the moment of infection. Earlier attacks looked for a hidden marker inside cached files. This one simply compares file sizes against an expected value. The pasted command searches Firefox profile folders for files starting with "f_", copies the matching file to the Temp folder as a VBScript and runs it. Further stages then run PowerShell, compile code on the victim's machine and inject it into the legitimate timeout.exe process to target browser and device credentials. The malware contacts three command domains and uses a scheduled task launching a Python payload to persist.

Microsoft did not say who was behind the campaign, how many sites were compromised, or which credential stealer was used at the end. It advises defenders to hunt across browser activity, Run dialog history in the RunMRU registry key, WScript and PowerShell child processes, and scheduled tasks, rather than relying on download events.

Summarised by CISO AI from iTnews, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.