By Interestana AI Editorial — AI-drafted, human-overseen. How we report
ClickFix Attack Leverages Browser Cache for Windows Payload Delivery

A new variant of the ClickFix attack has been identified, employing a novel method to deliver malicious payloads by exploiting the web browser's cache to bypass Windows execution limitations. This attack pattern deviates from traditional methods that involve downloading and executing remote payloads directly. Instead, compromised websites are used to pre-fetch a script payload, which is then disguised as a Portable Network Graphics (PNG) file and stored within the browser's cache. Microsoft Threat Intelligence detailed this discovery in a post on the social media platform X.
The technique involves a malicious script that, when executed, initiates a request to a compromised website. This website, in turn, serves a script payload that is designed to be interpreted by the browser as a PNG image. This obfuscation is crucial for evading detection mechanisms that might flag direct script execution. Once the payload is cached by the browser, the attacker can then trigger its execution through a subsequent action, such as a user clicking on a specific element or navigating to a particular part of the compromised site. This cached payload can then be processed by the Windows operating system, effectively bypassing the security measures that prevent direct execution of downloaded scripts or executables from untrusted sources.
This method of attack is particularly concerning because it leverages a common and often overlooked component of web browsing: the browser cache. Caches are designed to speed up web page loading by storing frequently accessed resources locally. Attackers are exploiting this functionality to hide malicious code in plain sight, making it more difficult for security software to identify and neutralize threats. The use of a PNG disguise further complicates detection, as many security tools may not perform deep inspection of cached files that appear to be legitimate image assets. The reliance on user interaction, such as a click, also adds a social engineering element to the attack, making it more effective against unsuspecting users.
Microsoft Threat Intelligence's analysis highlights the evolving tactics of cybercriminals in finding new avenues to deliver malware. The ClickFix attack, in this iteration, demonstrates a sophisticated understanding of browser and operating system interactions. By manipulating the browser cache, attackers can create a persistent threat that is not immediately apparent. This necessitates a multi-layered security approach, including robust endpoint protection, regular security awareness training for users, and vigilant monitoring of network traffic and system processes for any unusual activity that might indicate a cached payload is being prepared for execution. The effectiveness of this attack underscores the importance of keeping web browsers and security software updated to patch potential vulnerabilities and improve threat detection capabilities.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.