Microsoft Warns of ClickFix Attacks Using Browser Cache to Hide Malicious Payloads
Brief
Microsoft Threat Intelligence has uncovered a ClickFix campaign in which compromised websites abuse browser cache storage to conceal malicious scripts and evade common detection techniques.
Rather than directly downloading a payload when the victim runs a command, the attackers pre-stage the malware in the browser cache, disguising it as a PNG image file.
The approach also addresses a practical limitation of ClickFix attacks: the restricted character length available in the Windows Run dialog.
Microsoft Warns of ClickFix Attacks Using Browser Cache
By placing the larger payload into the browser cache before the victim interacts with the fake prompt, attackers only need to trick the user into launching a relatively short command.
ClickFix is a social-engineering technique that persuades victims to manually execute attacker-provided commands.
