www.infosecurity-magazine.com 6 Oct 2026, 15:00 UTC

ClickFix Attack Hides VBScript in Browser Cache to Steal Credentials

ON 6 October 2026, Infosecurity reported a ClickFix campaign that hides a VBScript payload inside the browser cache, masquerading as an image so the script is already present on the victim’s device when they are tricked into running a command through Windows Run. Microsoft Threat Intelligence described the technique, noting a cluster of compromised websites directing visitors to the attacks. In this campaign, a fake CAPTCHA prompts users to open Run, paste content from the clipboard, and press Enter.

The attacker’s workflow relies on pre-fetching the payload into the browser cache rather than downloading it after the user action. The pasted command launches cmd[.]exe to search the browser profile for cached files beginning with “f_” and to compare each file’s size against an expected value. Instead of scanning for a marker, the payload is identified by size, copied to a temporary folder with a .vbs extension, and executed via wscript[.]exe.

The VBScript then gathers host details via Windows Management Instrumentation (WMI), retrieves a PowerShell script, and runs it with an execution policy bypass. Later stages compile and load further code in memory, injecting into timeout[.]exe to capture credentials from browsers and devices.

For persistence, the malware creates a scheduled task after unpacking a Python copy via tar[.]exe and launching a Python payload with pythonw[.]exe, providing a foothold surviving reboots. Microsoft Defender Antivirus flags the activity as Trojan:Win32/ClickFix and Trojan:Win32/TermFix, and recommends cloud-delivered protection, network protection, application control, and PowerShell script-block logging.

Defenders are advised to look for atypical browser activity, unusual WScript and PowerShell use, suspicious scheduled-task events, and RunMRU registry entries, noting that a CAPTCHA should not prompt users to run code.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline