A new "ClickFix" social engineering campaign has been identified that leverages browser caches to conceal malicious VBScript payloads. The technique, detailed by Microsoft Threat Intelligence on October 3, involves compromised websites pre-fetching a script disguised as an image into a visitor's browser cache. This allows the payload to be present on the victim's device before they are tricked into executing it.
The attack begins with a fake CAPTCHA pop-up instructing users to open the Windows Run dialog, paste a command from their clipboard, and press Enter. By pre-loading the VBScript into the cache, the attackers circumvent the Run dialog's character limit, as the pasted command only needs to locate and launch an existing file.
The command executed by the victim runs `cmd.exe`, which then searches the browser profile folder for cached files starting with "f_". Unlike previous iterations that might have searched for specific content markers, this campaign identifies the malicious file by comparing its size against an expected value. Once located, the file is copied to a temporary folder, renamed with a `.vbs` extension, and executed using `wscript.exe`.
The VBScript then proceeds to gather host details via Windows Management Instrumentation (WMI). It subsequently fetches and executes a PowerShell script, bypassing the system's execution policy. Later stages of the attack involve compiling and loading additional code in memory, which is then injected into the legitimate `timeout.exe` process. This injected code is designed for credential theft, targeting browsers and other device information.
For persistence, the malware connects to attacker-controlled servers and unpacks a Python interpreter using the built-in `tar.exe` utility. It then establishes a scheduled task that runs a Python payload through `pythonw.exe`, ensuring the attackers maintain a foothold on the compromised system even after a reboot.
Microsoft Defender Antivirus identifies and blocks malicious command execution related to this campaign as `Trojan:Win32/ClickFix` and `Trojan:Win32/TermFix`. Microsoft recommends several protective measures, including enabling cloud-delivered protection, network protection, application control, and PowerShell script-block logging. For threat hunting, the company advises looking beyond typical download events to analyze browser activity, unusual `WScript`, PowerShell, and scheduled task activity, and the `RunMRU` registry key, which logs commands entered into the Run dialog. Microsoft also emphasized that legitimate CAPTCHA challenges should never prompt users to execute code.






