Image: assets.infosecurity-magazine.com · rights & removal
ClickFix Attack Hides VBScript Payload in Browser Cache
Reporting by InfoSecurity MagazineRead the original at infosecurity-magazine.com
Executive Summary
Facts Only
* A ClickFix campaign hid a VBScript payload in the browser cache disguised as an image.
* The attack involved tricking users into running commands via Windows Run using a fake CAPTCHA.
* Attackers pre-fetched the payload into the browser cache instead of downloading it directly.
* The pasted command ran cmd.exe, which searched for cached files beginning with "f\" and compared file sizes to expected values.
* A file was copied with a .vbs extension to a temporary folder and executed with wscript.exe.
* The VBScript gathered host details using Windows Management Instrumentation (WMI).
* The script fetched and ran a PowerShell script, bypassing execution policy restrictions.
* Further stages compiled and loaded code in memory by injecting it into the legitimate timeout.exe process for credential theft.
* Malware connected to attacker servers and unpacked Python using tar.exe.
* A scheduled task was created to run a Python payload via pythonw.exe for persistence across reboots.
* Microsoft Defender Antivirus blocked execution of Trojan:Win32/ClickFix and Trojan:Win32/TermFix.
Full Take
From the original · InfoSecurity Magazine
A ClickFix campaign has been observed hiding a VBScript payload in the browser cache, disguised as an image, so the script was already on the device when the victim was tricked into running a command through Windows Run. Microsoft Threat Intelligence described the technique in a post on X on October 3, saying a cluster of compromised websites was leading visitors to the attacks.Read the full story at infosecurity-magazine.com
Sentinel — Human
This text reads like an accurate, synthesized summary of a technical threat analysis, likely drawn from official threat intelligence sources, presented clearly for educational purposes.
