Sophisticated ClickFix Campaign Leverages Browser Cache to Mask Malicious VBScript Payloads

A burgeoning threat campaign utilizing the "ClickFix" social engineering technique has introduced a clever, stealthy evolution in its delivery mechanism, catching the attention of cybersecurity researchers. Recent observations by Microsoft Threat Intelligence reveal that attackers are now pre-fetching VBScript payloads directly into a user’s browser cache, disguising them as innocuous image files. This strategic shift ensures that the malicious code is already resident on the victim’s machine before they are even prompted to initiate the attack, allowing the threat actors to bypass traditional network-based detection systems and circumvent the limitations of the Windows Run dialog.

The campaign, which Microsoft detailed in an advisory posted to social media on October 3, relies on a network of compromised websites. These sites are engineered to intercept traffic and redirect unsuspecting visitors toward a deceptive trap. Once a user lands on one of these malicious pages, they are presented with a fake CAPTCHA pop-up. The interface is designed to look like a standard security verification tool, instructing the user to perform a seemingly benign set of actions: open the Windows Run dialog (typically via the Win+R keyboard shortcut), paste a pre-copied command from their clipboard, and press Enter.

The Evolution of ClickFix Tactics

ClickFix has increasingly become a preferred method for cybercriminals looking to bridge the gap between social engineering and technical execution. By manipulating the user into performing the final stage of the infection, attackers effectively turn the victim into an unwitting accomplice. Historically, ClickFix campaigns would prompt a user to download and execute a file directly from a malicious link. However, this older method often triggered browser warnings or endpoint security alerts, as the sudden download and execution of an executable file are classic red flags for security software.

The new approach documented by Microsoft circumvents these hurdles by decoupling the delivery of the payload from the user’s manual action. Because the script is already stored in the browser’s cache—having been "pre-fetched" by the malicious site during the user’s initial visit—the command that the user is tricked into pasting does not need to reach out to an external server to download anything. Instead, the command simply instructs the system to locate the file already sitting on the hard drive.

Furthermore, this method addresses a long-standing technical hurdle: the character limit of the Windows Run dialog. By keeping the actual malicious payload off the command line and buried in the browser cache, the attackers only need to input a short, efficient command to locate and launch the file. This makes the malicious command string look significantly less suspicious to an observant user and prevents it from being truncated by the system’s input limitations.

Browser Cache: A Hidden Harbor for Malware

The mechanics of this infection are both precise and difficult to track for the average user. Once the victim pastes the malicious command into the Run box and hits Enter, the Windows command processor (cmd.exe) is invoked. The script is programmed to scan the user’s browser profile directory, specifically hunting for files that begin with the prefix "f_."

In previous iterations of such attacks, malicious actors often searched for specific byte patterns or text markers within the files to identify their payload. This new campaign adopts a more efficient, size-based verification method. The malicious command compares the size of the cached files against a predetermined value known to the attacker. Once a match is found, the script copies the identified file into a temporary folder, renames it with a .vbs extension, and executes it using wscript.exe.

By operating in this manner, the attackers effectively hide their payload in plain sight. Files residing in the browser cache are often ignored by users and can even be overlooked by some basic security scanning tools that focus primarily on executable downloads or temporary files in common system directories. Once the VBScript is successfully executed, it begins the process of gathering sensitive host information. It leverages Windows Management Instrumentation (WMI) to perform reconnaissance on the victim’s system, identifying the environment and its vulnerabilities.

Following the initial reconnaissance, the VBScript reaches out to an external command-and-control server to fetch a secondary PowerShell script. This script is executed with its execution policy bypassed, a common technique that allows the malware to run even if the system is configured to restrict unauthorized scripts. The infection eventually matures by compiling and loading further malicious code directly into the system’s volatile memory. This process, often referred to as "fileless" execution, is particularly dangerous because it leaves minimal forensic evidence on the disk. The final stage of this process involves injecting the code into the legitimate timeout.exe process, a process frequently used by the operating system, which helps the malware hide its activity from casual inspection while it begins siphoning credentials from browsers and other sensitive applications on the device.

Establishing Persistence and Long-Term Access

Once the primary infection is established, the attackers move to secure a permanent foothold on the victim’s machine. The malware connects back to the attacker’s infrastructure to unpack a copy of Python, utilizing the native tar.exe utility already present in Windows. By using built-in system tools—a technique known as "living off the land"—the attackers minimize the need to introduce foreign executables that might trigger antivirus alerts.

After unpacking the Python environment, the malware establishes a scheduled task. This task is configured to execute a Python payload via pythonw.exe automatically. Because it is tied to the Windows Task Scheduler, the malicious activity will restart every time the user logs in or the machine reboots, granting the threat actors long-term, persistent access to the compromised system. This persistence allows the attackers to maintain their presence, exfiltrate data, or deploy additional malware at their leisure.

Microsoft has responded to this campaign by updating its security products. Microsoft Defender Antivirus now provides coverage for these malicious command patterns, identifying them under the detections Trojan:Win32/ClickFix and Trojan:Win32/TermFix. However, Microsoft emphasizes that technical signatures are only one part of the defense. To effectively mitigate the risks posed by such sophisticated social engineering, the company recommends a multi-layered security approach. This includes enabling cloud-delivered protection, utilizing network protection to block connections to known malicious domains, implementing robust application control policies, and ensuring that PowerShell script-block logging is active.

Vigilance and Hunting Recommendations

For security professionals and IT administrators tasked with hunting for these threats, the advice from Microsoft is to look beyond the standard indicators of a download event. Because the payload is already in the cache, the primary "download" may have happened minutes or hours before the actual attack was initiated. Security teams should prioritize monitoring for unusual behavior, such as the unexpected execution of wscript.exe or suspicious PowerShell activity originating from browser-related processes.

Additionally, administrators should scrutinize the RunMRU (Most Recently Used) registry key. This key stores the commands that users have manually typed or pasted into the Windows Run box, providing a critical trail of evidence for forensic investigators to identify which users may have been targeted and what commands were executed.

Ultimately, the most effective defense remains user education. Microsoft stresses that a legitimate CAPTCHA or security verification prompt will never ask a user to open the Windows Run dialog or paste and execute code. Any website that demands such actions is immediately suspect and should be avoided. By fostering a culture of healthy skepticism regarding pop-up instructions—especially those that attempt to bypass standard browser security by leveraging system-level tools—organizations can significantly reduce the likelihood of falling victim to these evolving ClickFix threats. As the landscape of cybercrime continues to shift toward more stealthy and user-assisted attack vectors, the combination of robust technical defenses and informed user behavior remains the primary barrier against persistent threats.

Leave a Reply

Your email address will not be published. Required fields are marked *