Phishing
ClickFix hides its payload in the browser cache
A ClickFix variant pre-loads a VBScript into the browser cache as a fake PNG, so the Run dialog command only has to copy and launch it. How to block and hunt it.
Microsoft Threat Intelligence has described a ClickFix campaign, seen on a cluster of compromised websites in early October 2026, that delivers its first script before the victim types anything. While the fake Cloudflare check is on screen, the page has already pulled a VBScript into the browser's cache disguised as a PNG image. The command the visitor is then talked into pasting into the Windows Run dialog only has to find that file, copy it and run it.
That changes two things defenders rely on. The pasted command makes no web request, so there is no download for the browser, proxy or endpoint product to flag at the moment of infection. And because the payload is already on disk, the attackers are no longer squeezed by the Run dialog's input limit of about 260 characters. Any Windows user who browses the web and can open Win+R is a possible target, and the chain ends in credential theft from browsers and the device.
How it works
ClickFix needs no software flaw. A web page shows a fake verification box, JavaScript writes a command to the clipboard when the visitor clicks it, and the page tells them to press Win+R, paste with Ctrl+V and hit Enter. The user runs the command with their own rights. The weak point for attackers has always been the Run box itself: its text field is capped at MAX_PATH, 260 characters, so the command usually has to reach out to the internet with PowerShell, mshta or msiexec, and that outbound request is what many detections watch for.
Cache smuggling moves the download earlier and makes it look harmless. Browsers store page resources on disk so they load faster next time. A compromised page can request a resource that it labels as an image, and the browser saves it to its cache like any other picture, even though the bytes are a script. Chromium-based browsers write any cached item larger than 16 KB to its own file named f_ plus a hexadecimal number, with no header added, so a straight copy of that file is the original script.
In this campaign the pasted command starts cmd.exe, walks the browser profile folder for files whose names start with f_ and compares each one's size with a value hardcoded by the attackers. Earlier cache smuggling attacks searched the cached content for a marker string; matching on size alone keeps the command short and gives scanners no tell-tale string to find. The expected size changed between variants. The matching file is copied to %LOCALAPPDATA%\Temp\t.vbs and run with wscript.exe, the Windows Script Host.
One report says the command searched Firefox profile folders. The f_ naming belongs to the Chromium cache format, so treat both browser families as in scope when you hunt.
What attackers are doing
The VBScript gathers host details through Windows Management Instrumentation (WMI) and then fetches a PowerShell script from cocojambo[.]us[.]com, running it with the execution policy bypassed. A later PowerShell stage downloads a file called cab.dat, runs its contents in a hidden window and compiles .NET code on the machine before starting timeout.exe. Further payloads load .NET assemblies straight into memory and inject code into that timeout.exe process, which then goes after credentials stored in browsers and on the device.
For persistence, the malware unpacks a copy of Python with the built-in tar.exe and creates a scheduled task that runs a Python payload through pythonw.exe, the windowless interpreter, so the foothold survives a reboot. Microsoft also listed capsysnet[.]vg and ciliabula[.]cc as attacker infrastructure. It has not named the operators or the final credential stealer, and no victim count has been published.
What to do
There is nothing to patch. Every step is configuration, detection or cleanup.
- Close the Run dialog for staff who never use it. The Group Policy setting "Remove Run menu from Start Menu" (User Configuration, Administrative Templates, Start Menu and Taskbar) removes Run and disables Win+R. It writes
NoRun= 1 (DWORD) underHKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer. It does not stop someone pasting into a terminal, so pair it with the next step. - Take away the script engine this chain needs. Setting the DWORD
Enabledto 0 underHKLM\Software\Microsoft\Windows Script Host\Settingsdisables Windows Script Host for every user on the machine, andwscript.exethen refuses to runt.vbs. On Windows 11 24H2 VBScript is an optional feature that is still on by default;DISM /Online /Remove-Capability /CapabilityName:VBSCRIPT~~~~removes it. Test first: some logon scripts and older line-of-business tools still use VBScript. - Block the infrastructure at DNS and the web proxy:
cocojambo[.]us[.]com,capsysnet[.]vgandciliabula[.]cc. Expect new domains in the next wave. - Turn on what Microsoft recommends: cloud-delivered protection and network protection in Defender, application control, and PowerShell script block logging (event ID 4104 in Microsoft-Windows-PowerShell/Operational).
To check whether you were already hit, look at the command trail first. The Run dialog saves every command in HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU; an entry that mentions f_, a browser profile path or t.vbs is a strong sign. In Microsoft Defender for Endpoint advanced hunting:
DeviceProcessEvents
| where FileName =~ "cmd.exe"
| where ProcessCommandLine has "f_"
and ProcessCommandLine has_any ("User Data", "Profiles", "Cache")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, ProcessCommandLine
Follow up with wscript.exe processes whose command line contains \Temp\t.vbs, timeout.exe started by PowerShell, tar.exe started by PowerShell, and scheduled tasks pointing at pythonw.exe in a user folder (schtasks /query /fo LIST /v shows the action of each task). On the disk, a leftover %LOCALAPPDATA%\Temp\t.vbs or cab.dat is enough to confirm.
If you find it, isolate the machine and reimage it rather than removing the task by hand, since in-memory stages and the Python payload may already have run. The payload targets credentials, so reset every password saved in that user's browsers, revoke their active sessions and tokens for cloud and SaaS accounts, and rotate any secrets the device held.
Detection has to move to the paste
This chain leaves no download event at the moment the user is fooled; the network fetch happened minutes earlier and looked like an image. Rules that wait for PowerShell or mshta to reach the internet from a Run command will see nothing until later stages. Write detections on what the pasted command does locally: cmd.exe reading browser cache folders, a file copied out of the cache and run as a script, and script hosts running from %TEMP%. Tell users that no CAPTCHA ever asks them to open Run and paste something, a point Microsoft repeated in this report.
Our safeguarding and hardening reviews check whether policies like NoRun and a disabled Script Host are actually applied, and security operations can run these hunts across your fleet. To ask about either, open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: The Hacker News, iTnews, Infosecurity Magazine, Microsoft Threat Intelligence on X, Crimson7 on browser cache smuggling, MalwareTech on the Run dialog limit, Chromium disk cache design, Microsoft Learn: adhering to system policy settings, Microsoft: disabling Windows Script Host, CISA countermeasure CM0078, VBScript deprecation timeline, Microsoft Learn: DeviceProcessEvents.