Microsoft Warns of ClickFix Attacks Hiding Malware in Browser Caches

Microsoft Threat Intelligence has identified a ClickFix campaign that hides malicious scripts in browser caches before tricking users into executing them, potentially allowing attackers to steal credentials without relying on a conventional malware download.

According to Microsoft’s disclosure on social media site X, attackers are using compromised websites to display fake verification prompts that instruct visitors to open Windows Run, paste a command and execute it.

The campaign uses a variation of ClickFix, a social-engineering technique that persuades users to run malicious commands under the guise of completing a CAPTCHA, fixing an error or performing another routine task.

Instead of downloading the initial script when the victim executes the command, the compromised website has already placed it in the browser cache, disguised as a PNG image. The pasted command searches the cached files, identifies the hidden script by its file size and copies it to a temporary location before executing it.

Microsoft says this approach conceals the larger payload and allows attackers to work around the character limit of the Windows Run dialog. It also avoids a fresh download of the initial script at the moment of execution.

Once running, the script collects information about the device and launches additional malware stages using PowerShell. Microsoft says the later stages load malicious code into a legitimate Windows process to target browser and device credentials.

Although browser-cache staging has been documented previously, Microsoft’s findings show the technique being used in an observed credential-theft campaign involving compromised websites.

Visiting an affected website doesn’t complete the attack. Users must still execute the supplied command. CAPTCHA checks and website verification prompts that ask visitors to open Windows Run, PowerShell or another command-line tool should be treated as suspicious.