Microsoft observed a ClickFix campaign where compromised websites cache a hidden payload in the victim’s browser, then trick the user into pasting a command (often via Win+R) that executes what’s already on the device. The method helps attackers hide the payload and get around Windows “Run” command-length limits while ultimately aiming to steal browser and device credentials.
How the Attack Worked
This campaign relies on a variant of the well-known ClickFix technique, but with a twist. Compromised websites pre-fetch a script payload into the browser cache disguised as a PNG file. Instead of downloading and executing a remote payload like the typical ClickFix pattern, the victim is prompted to paste and execute a command that simply runs the cached content that is already sitting on the device. In one observed chain, VBScript locates the cache entry by file size, copies it to a .vbs file in the Temp folder, and executes it. That step then pulls additional PowerShell stages, followed by in-memory .NET payloads and code injection into a legitimate process such as timeout.exe. The end goal is to target browser and device credentials.
Why It Succeeds
The technique is effective because it persuades users to run attacker-supplied commands under the pretext of CAPTCHA verifications, browser updates, or unexpected errors. Rather than asking users to download an unfamiliar program, it leverages built-in components of Windows and Mac, such as PowerShell, Windows Run, and Terminal, to activate the attack chain. Because the payload is already cached locally, the cache-smuggling approach can also bypass the character limit restrictions of the Windows Run dialog, roughly 260 characters, which would normally constrain how much malicious code could be pasted directly.
What to Watch For
Key warning signs include:
- A CAPTCHA or verification prompt instructing you to run code or paste commands
- Instructions that push you toward trusted system tools like Win+R, PowerShell, or Terminal instead of normal web-based verification steps
- "Fix" steps that are unusually complex for what should be a simple CAPTCHA or browser error
- A video conferencing site claiming a technical issue and offering a copy/paste command as the solution
A related example involved a bogus video conferencing site used against an employee at a financial services entity, where a fake technical issue was paired with a fix instructing the user to copy and paste a command that triggered a PowerShell and VBScript infection chain.
Building Resistance
Organizations should train employees, especially those in finance, executive roles, helpdesk functions, and anyone who frequently joins external video meetings, to recognize that a CAPTCHA should not ask users to run code. Staff should never paste commands from verification prompts into Run, Terminal, or PowerShell, and should treat such requests as potential initial access attempts. Reinforce that the dangerous part of this attack is that the user executes the command themselves, so the strongest defense is simply refusing to run any command provided by a website pop-up or troubleshooting prompt, regardless of how convincing the error message appears.
Key findings
- Compromised sites “pre-fetch a script payload into the browser cache disguised as a PNG file,” then rely on the user to paste/execute a command that runs the cached content.
- The cache-smuggling approach can “bypass the character limit restrictions” of the Windows Run dialog (about 260 characters).
- Observed chain uses VBScript to locate a cache entry by file size, copy it to a .vbs file in Temp, and execute it, then pulls additional PowerShell stages.
- Later stages include in-memory .NET payloads and code injection into a legitimate process (“timeout.exe”) to target “browser and device credentials.”
- CrowdStrike reported a North Korea-aligned cluster using a bogus video conferencing site with a ‘technical issue’ and a copy/paste ‘fix’ command.
Who’s being targeted
- Commonly targeted roles: All employees, Finance, Executives, IT Helpdesk/Service Desk, Teams that frequently join external video meetings.
- Affected industries: Financial services, Any organization where users may follow web-based troubleshooting/CAPTCHA prompts.
- Attack channels: website.
- Impersonated: Website verification/CAPTCHA page (on a compromised site), Video conferencing service site (bogus).
Red flags to watch for
- A CAPTCHA or verification prompt instructs you to run code or paste commands
- Instructions push you to use trusted system tools (Win+R/PowerShell) rather than normal web verification steps
- ‘Fix’ steps are unusually complex for a simple CAPTCHA or browser error
- Meeting site asks you to run commands to ‘fix’ audio/video or load a meeting
- Unexpected ‘technical issue’ banner paired with step-by-step command execution
- Fix requires PowerShell/VBScript instead of a normal in-browser update
Frequently asked questions
What is a ClickFix attack?
ClickFix is a social engineering technique where compromised websites pre-fetch a script payload into the browser cache disguised as a PNG file, then trick the victim into pasting and executing a command that runs the cached content.
Why do ClickFix commands bypass the Windows Run character limit?
Because the cache-smuggling approach lets attackers reference already-cached content rather than embedding a long payload directly in the command, which can bypass the character limit restrictions of the Windows Run dialog, about 260 characters.
What should employees do if a CAPTCHA asks them to run a command?
They should stop immediately and treat it as a scam, since a CAPTCHA should not ask users to run code, and pasting commands from verification prompts into Run, Terminal or PowerShell should be treated as a potential initial access attempt.
What is the end goal of these ClickFix campaigns?
The observed chain pulls additional PowerShell stages, uses in-memory .NET payloads, and injects code into a legitimate process to target browser and device credentials.
Read the video transcript
Imagine a CAPTCHA that says: “Press Win+R, paste this command to prove you’re human.” That’s the ClickFix scam. Behind that page, a compromised site has already stashed malware in your browser cache disguised as a PNG. When you paste their command, it quietly grabs that cached file, saves it as a VBScript in Temp, runs PowerShell, and starts stealing browser and device credentials. We’ve even seen bogus video-conferencing sites say, “Technical issue detected, copy this command to fix audio and load the meeting.” The trick: they use trusted tools like Win+R, PowerShell, or Terminal so it feels safe, even though no download ever appears. A real CAPTCHA or meeting page will never ask you to run commands. If any website tells you to use Win+R, PowerShell, or Terminal, stop and report it to IT immediately.