ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter.

The instruction looks simple, but it makes the victim run the attacker’s command. The campaign is concerning because its main script is placed on the computer before that step, hiding in the browser cache rather than arriving as an obvious download.

Microsoft Threat Intelligence identified the activity in a cluster of compromised websites. Microsoft described in its published findings how attackers disguise the fetched script as a PNG file, allowing a shorter command to fit in Windows Run.

The public disclosure outlines a multistage attack targeting credentials. That design can weaken controls focused only on newly downloaded files and network requests at execution time.

It also continues a broader move toward human-led infection chains, seen in earlier browser cache smuggling reporting, where a routine-looking prompt becomes the first step toward credential theft and persistent access.

ClickFix Fake CAPTCHA Attack Executes Malware

The attack starts after a victim reaches an altered website. A fake verification or repair panel asks them to use Win+R, paste material from the clipboard, and run it.

A legitimate CAPTCHA keeps the verification inside the browser and never requires a person to execute a system command. Behind the page, the VBScript payload has already been stored in the browser profile cache as a PNG-like resource.

The pasted command opens a command processor to search cache files in locations such as the Firefox profile folder and compares their sizes with a value set by the attackers.

When it finds a match, the command copies the cached content into a temporary VBScript file and starts it through Windows Script Host.

Output and errors are suppressed, reducing signs that anything happened. The expected file size differs between variants, making a fixed size-based rule unreliable.

This split lets criminals avoid placing a long script directly in the Run box, while removing the need to fetch the main payload after the victim acts.

Earlier coverage of fake CAPTCHA phishing tactics shows why the model is effective: it abuses trust in security checks and shifts execution onto the user.

The VBScript gathers device information through Windows Management Instrumentation and retrieves a PowerShell script. Later activity downloads another payload, invokes .NET compilation tools, and starts a legitimate Windows utility. Subsequent code is loaded into memory and injected into that process to pursue browser-stored and device credentials.

Credential Theft

The campaign also tries to stay on the device. It changes the current user’s PowerShell setting to Bypass, unpacks Python components, and creates a scheduled task that launches a Python payload through a windowless interpreter.

These steps can give attackers a way back after the browser window is closed. Security teams should look beyond conventional download alerts.

Useful investigation points include browser-cache activity, the RunMRU registry key, unusual child processes from WScript or PowerShell, and new scheduled tasks.

Similar FileFix cache smuggling attacks demonstrate how hiding payloads in apparently harmless browser content can reduce visible network activity.

Microsoft recommends enabling cloud-delivered protection, web protection, network protection, application control, and PowerShell script-block logging.

Defenders should also investigate alerts for suspicious command execution and outbound connections, while users should close any page that asks them to paste commands into Run, Terminal, or PowerShell.

The main safeguard remains straightforward: CAPTCHA checks do not need command-line access. The campaign depends on visitors accepting instructions outside the browser, not simply viewing the page.

Recognizing that boundary can prevent the initial command from running, even when the payload is already cached. These findings describe a credential-focused intrusion chain, but Microsoft did not publish a victim count or identify the operators in this disclosure.

Cache staging does not mean the activity is invisible: suspicious script execution, process relationships, outbound connections, and persistence changes still provide opportunities for detection and investigation.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain/path cocojambo[.]us[.]com/alfa Location from which the initial VBScript retrieves a PowerShell script.
Domain capsysnet[.]vg Source of an additional memory-resident stage.
Domain ciliabula[.]cc Destination of outbound connections from the injected process.
File path %LOCALAPPDATA%Tempt.vbs Temporary VBScript payload copied from a matching browser-cache entry.
File name v.ps1 PowerShell script retrieved by the VBScript stage.
File name cab.dat Downloaded next-stage payload whose contents are subsequently executed.
File name prefix f_ Prefix used to select cache-file candidates before comparing their byte lengths.
Directory %LOCALAPPDATA%MozillaFirefoxProfiles Example browser-profile directory searched for cached payload content.
Executable cmd.exe Legitimate command processor abused to enumerate and copy cached files; not malicious by itself.
Executable wscript.exe Legitimate Windows Script Host executable used to launch the temporary VBScript.
Executable csc.exe Legitimate .NET compilation tool invoked during the attack chain.
Executable cvtres.exe Legitimate resource-conversion tool involved in the observed .NET compilation activity.
Executable timeout.exe Legitimate Windows utility targeted for code injection.
Executable tar.exe Legitimate archive utility used to unpack Python components.
Executable pythonw.exe Legitimate windowless Python interpreter used by the persistence task.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache appeared first on Cyber Security News.