Microsoft spots new twist on ClickFix "cache smuggling"

By
Follow google news

Attackers now fish their malware out of the browser cache by file size alone.

Microsoft has outlined a new ClickFix campaign that hides malware in victims' browser caches, then finds it again by file size alone.

Microsoft spots new twist on ClickFix "cache smuggling"

The tech giant's Threat Intelligence group said it had noticed a cluster of compromised websites pre-fetched a script payload into visitors' browser caches, disguised as a PNG image file.

When victims were later tricked into running the attacker's command, the payload was "already on the device, loaded, and ready to be executed," Microsoft Threat Intelligence said.

ClickFix lures pose as verification or repair prompts and talk users into running commands themselves, in this case by pasting clipboard contents into the Windows Run dialog.

In the campaign Microsoft found, the lure posed as a Cloudflare human verification check, telling users to open the Windows Run dialog, paste and press Enter.

Staging payloads in the cache is not new in itself.

Security researcher Marcus Hutchins of Expel described the technique as cache smuggling in October 2025, noting that it avoids any conventional file download at the moment of infection.

Whereas earlier attacks searched cached files for a marker hidden in their contents, the campaign  Microsoft detailed simply compares each file's size against an expected value.

The command searches Firefox profile folders for files with names that begin with "f_". 

It then copies the size-matching file to the Temp folder as a VBScript file and runs it with the Windows Script Host (wscript.exe) application.

The expected size varied between variants of the attack, Microsoft said, with the approach helping to hide the payload and to get around the Run dialog's character limit, since the pasted command only has to locate and launch the script.

From there, the chain fetches further PowerShell stages, compiles .NET code on the victim's machine and injects it into the legitimate timeout.exe process to target browser and device credentials.

The malware contacts three control and command domains cocojambo[.]us[.]com, capsysnet[.]vg and ciliabula[.]cc, and uses a scheduled task launching a Python payload for persistence.

Microsoft did not say who was behind the campaign, how many sites were compromised, or which credential stealer sat at the end of the chain.

The company advises defenders to hunt across browser activity, Run dialog history in the RunMRU registry key, WScript and PowerShell child processes, and scheduled tasks, rather than relying on download events.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Home Affairs orders gov-wide 'legacy' system stocktake within six months

Home Affairs orders gov-wide 'legacy' system stocktake within six months

OpenAI agent accessed "credentials" via Medicare data portal

OpenAI agent accessed "credentials" via Medicare data portal

Citrix confirms exploitation of Netscaler zero-day bugs

Citrix confirms exploitation of Netscaler zero-day bugs

Teen researcher with AI hackbot cracks Microsoft's Titan analytics

Teen researcher with AI hackbot cracks Microsoft's Titan analytics

Log In

  |  Forgot your password?