ClickFix Attack Uses Browser Cache To Hide Malware Payload
Microsoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.

Microsoft Threat Intelligence has traced a ClickFix cache-smuggling method in which compromised websites preload a disguised script into a victim's browser cache, then a pasted Run command recovers the payload by file size alone.
Microsoft Threat Intelligence found compromised websites pre-fetching a script payload into visitors' caches while disguising it as a PNG image.
Once the lure had persuaded a victim to paste a command into the Windows Run dialog, the payload was already on the device and ready to execute.
The approach changes the weak point in a familiar ClickFix pattern.
These attacks commonly impersonate verification or repair prompts, then rely on the user to run the attacker's instructions.
In this campaign, the prompt posed as a Cloudflare human verification check and told the user to open Run, paste the clipboard contents and press Enter.
Staging code in a cache is not new.
Security researcher Marcus Hutchins of Expel described cache smuggling in October 2025 as a way to avoid a conventional file download at the moment of infection.
The newer twist is the lookup method: instead of searching cached files for a hidden marker in their contents, the command checks cached file sizes against an expected value.
That shorter search helps the attack fit inside the Run dialog's character limit.
The command looks through Firefox profile folders for files whose names begin with "f_", copies the file with the matching size into the Temp folder as a VBScript file, and launches it with Windows Script Host.
The size target changed across variants.
After the VBScript stage runs, the chain retrieves additional PowerShell stages, compiles .NET code on the machine and injects it into the legitimate timeout.exe process.
The final objective is credential theft from browsers and devices.
The malware used three command-and-control domains in the activity Microsoft described.
For defenders, the operational condition is narrow but concrete: a browser cache entry that looks inert can become executable once social engineering supplies the local command that finds and launches it.

















