Microsoft has outlined a new ClickFix campaign that hides malware in victims' browser caches, then finds it again by file size alone.
The tech giant's Threat Intelligence group said it had noticed a cluster of compromised websites pre-fetched a script payload into visitors' browser caches, disguised as a PNG image file.
When victims were later tricked into running the attacker's command, the payload was "already on the device, loaded, and ready to be executed," Microsoft Threat Intelligence said.
ClickFix lures pose as verification or repair prompts and talk users into running commands themselves, in this case by pasting clipboard contents into the Windows Run dialog.
In the campaign Microsoft found, the lure posed as a Cloudflare human verification check, telling users to open the Windows Run dialog, paste and press Enter.
Staging payloads in the cache is not new in itself.
Security researcher Marcus Hutchins of Expel described the technique as cache smuggling in October 2025, noting that it avoids any conventional file download at the moment of infection.
Whereas earlier attacks searched cached files for a marker hidden in their contents, the campaign Microsoft detailed simply compares each file's size against an expected value.
The command searches Firefox profile folders for files with names that begin with "f_".
It then copies the size-matching file to the Temp folder as a VBScript file and runs it with the Windows Script Host (wscript.exe) application.
The expected size varied between variants of the attack, Microsoft said, with the approach helping to hide the payload and to get around the Run dialog's character limit, since the pasted command only has to locate and launch the script.
From there, the chain fetches further PowerShell stages, compiles .NET code on the victim's machine and injects it into the legitimate timeout.exe process to target browser and device credentials.
The malware contacts three control and command domains cocojambo[.]us[.]com, capsysnet[.]vg and ciliabula[.]cc, and uses a scheduled task launching a Python payload for persistence.
Microsoft did not say who was behind the campaign, how many sites were compromised, or which credential stealer sat at the end of the chain.
The company advises defenders to hunt across browser activity, Run dialog history in the RunMRU registry key, WScript and PowerShell child processes, and scheduled tasks, rather than relying on download events.

HPE Networking Day Sydney
iTnews Resilience, Rewired Breakfast
RIMPA Live Convention 2026
What’s Next?
iTnews Benchmark Security Awards 2026



