Skip to content

Image: assets.infosecurity-magazine.com · rights & removal

Executive Summary

A ClickFix campaign utilized social engineering to trick victims into executing commands via a fake CAPTCHA, prompting them to use the Windows Run dialog. The attackers pre-fetched a VBScript payload into the browser cache rather than downloading it directly. This method helped evade detection by bypassing command line restrictions and hiding the script from direct download scrutiny. Once executed, the VBScript searched cached files based on size matching, copied a file with a .vbs extension to a temporary folder, and ran it using wscript.exe. The payload then gathered host details via WMI, fetched a PowerShell script to execute without execution policy restrictions, and subsequently injected code into timeout.exe for credential theft from browsers and devices. Persistence was established by connecting to attacker servers, unpacking Python, creating a scheduled task that executed a Python payload via pythonw.exe, ensuring survival through reboots.

Facts Only

* A ClickFix campaign hid a VBScript payload in the browser cache disguised as an image.
* The attack involved tricking users into running commands via Windows Run using a fake CAPTCHA.
* Attackers pre-fetched the payload into the browser cache instead of downloading it directly.
* The pasted command ran cmd.exe, which searched for cached files beginning with "f\" and compared file sizes to expected values.
* A file was copied with a .vbs extension to a temporary folder and executed with wscript.exe.
* The VBScript gathered host details using Windows Management Instrumentation (WMI).
* The script fetched and ran a PowerShell script, bypassing execution policy restrictions.
* Further stages compiled and loaded code in memory by injecting it into the legitimate timeout.exe process for credential theft.
* Malware connected to attacker servers and unpacked Python using tar.exe.
* A scheduled task was created to run a Python payload via pythonw.exe for persistence across reboots.
* Microsoft Defender Antivirus blocked execution of Trojan:Win32/ClickFix and Trojan:Win32/TermFix.

Full Take

The technique demonstrates an evolution from simple file delivery to sophisticated, layered persistence. The initial mechanism relies on social engineering (ClickFix) to initiate action, but the actual payload delivery leverages stealth by hiding the artifact in browser cache rather than relying on traditional download vectors. This shift indicates a focus on evading signature-based detection systems and system monitoring during the initial compromise phase. The subsequent steps—using WMI for host enumeration, leveraging PowerShell execution policies, injecting into legitimate processes like timeout.exe, and establishing persistence via scheduled tasks—illustrate an operational methodology common in advanced threat actor tactics aimed at maximizing dwell time and evading endpoint security controls. The pattern observed is a coordinated sequence where initial user deception transitions seamlessly into post-exploitation lateral movement and persistence. The reliance on living off the land binaries (like wscript.exe, pythonw.exe, tar.exe) and system tools like WMI suggests an attempt to blend malicious activity within legitimate system operations, which tests the limits of standard behavioral monitoring. This raises questions about whether security measures focusing solely on file hashes or explicit command execution are sufficient against multi-stage attacks that operate within established operational frameworks. What controls should be prioritized to monitor for subtle correlations between browser history, system calls (WMI), and scheduled task creation when user interaction is involved?

From the original · InfoSecurity Magazine

A ClickFix campaign has been observed hiding a VBScript payload in the browser cache, disguised as an image, so the script was already on the device when the victim was tricked into running a command through Windows Run. Microsoft Threat Intelligence described the technique in a post on X on October 3, saying a cluster of compromised websites was leading visitors to the attacks.
Read the full story at infosecurity-magazine.com

Sentinel — Human

Confidence

This text reads like an accurate, synthesized summary of a technical threat analysis, likely drawn from official threat intelligence sources, presented clearly for educational purposes.

Signals Detected
low severity: Moderate sentence length variance; technical subject matter handled with clear, albeit slightly dense, prose.
low severity: Strong logical flow connecting the mechanism (ClickFix) to the execution (VBScript/WMI) to the persistence (Scheduled Task).
medium severity: Appears to synthesize information from a known security disclosure and subsequent analysis, likely referencing established threat intelligence reports.
low severity: Highly specific technical steps (e.g., checking for 'f_' files, using WMI/PowerShell) suggest either direct insider knowledge or meticulous aggregation of highly detailed security reports.
Human Indicators
The piece demonstrates a clear hierarchy of information typical of threat intelligence reporting (mechanism -> execution -> persistence -> defense advice).
The integration of specific threat names (Trojan:Win32/ClickFix) suggests grounding in real security advisories.
ClickFix Attack Hides VBScript Payload in Browser Cache | Huntaegis