ClickFix Tricks Users to Run Cached Malware

The Hacker News · High sophistication
Last updated October 6, 2026

Microsoft observed a ClickFix campaign where compromised websites cache a hidden payload in the victim’s browser, then trick the user into pasting a command (often via Win+R) that executes what’s already on the device. The method helps attackers hide the payload and get around Windows “Run” command-length limits while ultimately aiming to steal browser and device credentials.

How the Attack Worked

This campaign relies on a variant of the well-known ClickFix technique, but with a twist. Compromised websites pre-fetch a script payload into the browser cache disguised as a PNG file. Instead of downloading and executing a remote payload like the typical ClickFix pattern, the victim is prompted to paste and execute a command that simply runs the cached content that is already sitting on the device. In one observed chain, VBScript locates the cache entry by file size, copies it to a .vbs file in the Temp folder, and executes it. That step then pulls additional PowerShell stages, followed by in-memory .NET payloads and code injection into a legitimate process such as timeout.exe. The end goal is to target browser and device credentials.

Why It Succeeds

The technique is effective because it persuades users to run attacker-supplied commands under the pretext of CAPTCHA verifications, browser updates, or unexpected errors. Rather than asking users to download an unfamiliar program, it leverages built-in components of Windows and Mac, such as PowerShell, Windows Run, and Terminal, to activate the attack chain. Because the payload is already cached locally, the cache-smuggling approach can also bypass the character limit restrictions of the Windows Run dialog, roughly 260 characters, which would normally constrain how much malicious code could be pasted directly.

What to Watch For

Key warning signs include:

  • A CAPTCHA or verification prompt instructing you to run code or paste commands
  • Instructions that push you toward trusted system tools like Win+R, PowerShell, or Terminal instead of normal web-based verification steps
  • "Fix" steps that are unusually complex for what should be a simple CAPTCHA or browser error
  • A video conferencing site claiming a technical issue and offering a copy/paste command as the solution

A related example involved a bogus video conferencing site used against an employee at a financial services entity, where a fake technical issue was paired with a fix instructing the user to copy and paste a command that triggered a PowerShell and VBScript infection chain.

Building Resistance

Organizations should train employees, especially those in finance, executive roles, helpdesk functions, and anyone who frequently joins external video meetings, to recognize that a CAPTCHA should not ask users to run code. Staff should never paste commands from verification prompts into Run, Terminal, or PowerShell, and should treat such requests as potential initial access attempts. Reinforce that the dangerous part of this attack is that the user executes the command themselves, so the strongest defense is simply refusing to run any command provided by a website pop-up or troubleshooting prompt, regardless of how convincing the error message appears.

Key findings

  • Compromised sites “pre-fetch a script payload into the browser cache disguised as a PNG file,” then rely on the user to paste/execute a command that runs the cached content.
  • The cache-smuggling approach can “bypass the character limit restrictions” of the Windows Run dialog (about 260 characters).
  • Observed chain uses VBScript to locate a cache entry by file size, copy it to a .vbs file in Temp, and execute it, then pulls additional PowerShell stages.
  • Later stages include in-memory .NET payloads and code injection into a legitimate process (“timeout.exe”) to target “browser and device credentials.”
  • CrowdStrike reported a North Korea-aligned cluster using a bogus video conferencing site with a ‘technical issue’ and a copy/paste ‘fix’ command.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, IT Helpdesk/Service Desk, Teams that frequently join external video meetings.
  • Affected industries: Financial services, Any organization where users may follow web-based troubleshooting/CAPTCHA prompts.
  • Attack channels: website.
  • Impersonated: Website verification/CAPTCHA page (on a compromised site), Video conferencing service site (bogus).

Red flags to watch for

  • A CAPTCHA or verification prompt instructs you to run code or paste commands
  • Instructions push you to use trusted system tools (Win+R/PowerShell) rather than normal web verification steps
  • ‘Fix’ steps are unusually complex for a simple CAPTCHA or browser error
  • Meeting site asks you to run commands to ‘fix’ audio/video or load a meeting
  • Unexpected ‘technical issue’ banner paired with step-by-step command execution
  • Fix requires PowerShell/VBScript instead of a normal in-browser update
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a ClickFix attack?

ClickFix is a social engineering technique where compromised websites pre-fetch a script payload into the browser cache disguised as a PNG file, then trick the victim into pasting and executing a command that runs the cached content.

Why do ClickFix commands bypass the Windows Run character limit?

Because the cache-smuggling approach lets attackers reference already-cached content rather than embedding a long payload directly in the command, which can bypass the character limit restrictions of the Windows Run dialog, about 260 characters.

What should employees do if a CAPTCHA asks them to run a command?

They should stop immediately and treat it as a scam, since a CAPTCHA should not ask users to run code, and pasting commands from verification prompts into Run, Terminal or PowerShell should be treated as a potential initial access attempt.

What is the end goal of these ClickFix campaigns?

The observed chain pulls additional PowerShell stages, uses in-memory .NET payloads, and injects code into a legitimate process to target browser and device credentials.

Read the video transcript

Imagine a CAPTCHA that says: “Press Win+R, paste this command to prove you’re human.” That’s the ClickFix scam. Behind that page, a compromised site has already stashed malware in your browser cache disguised as a PNG. When you paste their command, it quietly grabs that cached file, saves it as a VBScript in Temp, runs PowerShell, and starts stealing browser and device credentials. We’ve even seen bogus video-conferencing sites say, “Technical issue detected, copy this command to fix audio and load the meeting.” The trick: they use trusted tools like Win+R, PowerShell, or Terminal so it feels safe, even though no download ever appears. A real CAPTCHA or meeting page will never ask you to run commands. If any website tells you to use Win+R, PowerShell, or Terminal, stop and report it to IT immediately.

Similar attacks

Phishers Hide “Funding” With Invisible Unicode

Phishers Hide “Funding” With Invisible Unicode

Microsoft reported a real, high-volume phishing campaign (up to millions of emails per day) that hid key “loan/funding” lure words using invisible Unicode characters to slip past email filters. The emails used disposable finance-themed domains and were often routed through ActiveCampaign…

September 4, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
EvilTokens Used Device-Code Phish to Fuel BEC

EvilTokens Used Device-Code Phish to Fuel BEC

Microsoft disrupted “EvilTokens,” a subscription cybercrime service that stole Microsoft account access using device-code phishing and then used AI-style automation to rapidly mine victims’ inboxes for payment and org-chart details. The goal was to quickly craft believable payment-fraud messages…

September 23, 2026