A new ClickFix attack method has been discovered, utilizing compromised websites to deceive users into executing malicious payloads hidden within their browser cache. Unlike traditional attacks that download and execute remote payloads, this approach involves pre-fetching a script payload disguised as a PNG file directly into the browser cache. This technique allows attackers to bypass character limit restrictions imposed by the Windows Run dialog, which truncates inputs exceeding about 260 characters. The attack chain observed by Microsoft involved the use of a Visual Basic Script that enumerates files in the browser's profile folder, comparing their byte length to an expected value. Once a match is found, a size-matching cache entry is copied to a temporary location and executed, with the VBScript designed to collect host information and fetch additional payloads using PowerShell.

This method of browser cache smuggling is not new to ClickFix attacks. Previously, similar techniques were used to deliver malware-laden ZIP archives. The ClickFix attack vector has become increasingly popular due to its ability to turn victims into unwitting delivery channels for malware, an attractive feature for cybercriminals and nation-state actors. The attack leverages familiar operating system tools such as PowerShell and Windows Run to execute its chain, thus reducing the likelihood of detection by security defenses. Recent campaigns have also seen threat actors exploiting known vulnerabilities in WordPress plugins to inject ClickFix lures into compromised websites.

To mitigate the threat posed by ClickFix, Microsoft advises implementing cloud-delivered, web, and network protection measures, along with application control and PowerShell script-block logging. Organizations are encouraged to enhance their security protocols to detect and block these sophisticated attack chains.