A new variation of the ClickFix social-engineering campaign is leveraging browser cache smuggling to deliver malicious payloads, Microsoft Threat Intelligence has warned. Rather than asking victims to download and run a file directly, compromised or fake websites pre-fetch a script into the browser cache disguised as a PNG. When a user is prompted to paste a command into a trusted tool (for example the Windows Run dialog via Win + R), the cached content is executed instead of a freshly downloaded file.
This technique helps attackers bypass Windows’ Run input length limits (roughly 260 characters) and conceal the payload from typical endpoint controls.
In the observed chain, the staged payload is a VBScript that runs cmd[.]exe to enumerate files in the user’s browser profile directory, then copies a size-matched cache entry to a temporary VBScript file and executes it via wscript[.]exe. The VBScript harvests system information through WMI, downloads a PowerShell component from an external server, and then installs a second-stage payload that ultimately loads .NET assemblies into memory and injects code into a legitimate process (timeout[.]exe).
A subsequent PowerShell stage reaches more payloads hosted remotely, culminating in additional malware families such as GeniexLoader and GeniexRAT. The attack also uses in-memory techniques to evade detection and has been tied to broader ClickFix campaigns, with evidence pointing to compromised WordPress sites (e.g., CVE-2026-6854) being abused to host lures.
Microsoft and CrowdStrike advise organisations to bolster cloud/web/network protections, enable PowerShell script-block logging, and hunt for anomalous Run, WScript/PowerShell child processes, and suspicious browser activity.