Ethical Hacking News
ClickFix attacks have become an increasingly popular method of social engineering used by cybercriminals and nation-state actors to gain access to systems and data. A new type of ClickFix attack has emerged, utilizing compromised websites to trick users into executing a malicious payload cached in a web browser's cache. This new approach allows attackers to bypass the character limit restrictions imposed by the Windows Run dialog, making it more difficult for security controls to detect and prevent these types of attacks. By understanding the tactics, techniques, and procedures (TTPs) used by attackers and implementing robust security controls, organizations can protect themselves against these types of threats.
ClickFix attacks are becoming increasingly popular among cybercriminals and nation-state actors to gain access to systems and data. A new type of ClickFix attack uses compromised websites to trick users into executing a malicious payload cached in their web browser's cache. The attack bypasses Windows Run dialog character limit restrictions, making it harder for security controls to detect and prevent these attacks. The attackers use Visual Basic Script (VBScript) as the payload, which invokes cmd.exe to enumerate files and harvest host information. The ClickFix ecosystem has evolved with the availability of phishing kits, making it easier for attackers to launch these campaigns. Organizations are recommended to implement cloud-delivered, web, and network protection, as well as PowerShell script-block logging, to counter the threat. ClickFix attacks have been linked to nation-state threat actors, including the Russian state-sponsored adversary Sandworm. Users and organizations need to raise awareness about the risks associated with ClickFix attacks and implement robust security controls to detect and prevent them.
ClickFix attacks have become an increasingly popular method of social engineering used by cybercriminals and nation-state actors to gain access to systems and data. A new type of ClickFix attack has emerged, utilizing compromised websites to trick users into executing a malicious payload cached in a web browser's cache. This new approach allows attackers to bypass the character limit restrictions imposed by the Windows Run dialog, making it more difficult for security controls to detect and prevent these types of attacks.
The ClickFix attack works by pre-fetching a script payload into the browser cache disguised as a PNG file. When the victim is prompted to paste and execute a malicious command, the cached website content is executed instead, allowing the attackers to bypass the need for remote execution. This method of delivery makes it more challenging for security controls to detect and prevent the attack, as the payload is already present on the device.
The attackers use a Visual Basic Script (VBScript) as the payload, which invokes "cmd.exe" to recursively enumerate files whose names start with "f_" in the browser's profile folder. The script compares each file's byte length with an expected value, copying a size-matching cache entry to a temporary location and executing it with wscript.exe. The expected size varies across variants, making it more difficult for security controls to detect and prevent the attack.
The VBScript is also designed to harvest host information via Windows Management Instrumentation (WMI), fetch a PowerShell script from an external server, and launch it. The PowerShell script serves as a conduit for an intermediate PowerShell payload that downloads the next stage. Once the file is downloaded, its contents are read and executed in a hidden window. The attack eventually paves the way for .NET assemblies that are loaded into memory and inject code into a newly launched legitimate Windows process with the aim of targeting browser and device credentials.
The use of ClickFix attacks has become a popular method of social engineering due to its effectiveness in persuading users to run attacker-supplied commands under the pretext of CAPTCHA verifications, browser updates, or unexpected errors. The attack capitalizes on the "troubleshooting" theme to trick users into infecting their own systems, effectively bypassing security controls.
The ClickFix ecosystem has evolved considerably since its early days, fueled by the availability of phishing kits that can automate the creation of "Fix-type" attacks. The commoditization of these kits has further lowered the barrier to entry and accelerated the frequency of these campaigns. The anatomy of a ClickFix attack is a multi-step chain that leads victims to a fake website, serves the problem trigger, provides the "solution," and instructs the user to copy a command to address the issue.
To counter the threat, organizations are recommended to implement cloud-delivered, web, and network protection, application control, and PowerShell script-block logging. They should also go beyond download events and hunt for suspicious browser activity, RunMRU registry key, WScript/PowerShell child processes, and scheduled tasks.
In recent months, ClickFix attacks have been linked to nation-state threat actors, including the Russian state-sponsored adversary Sandworm. The attackers have targeted suspected Ukrainian employees working at organizations in France, the U.S., and Canada with ClickFix attacks to deceive them into running PowerShell commands that download a VBScript payload.
The use of ClickFix attacks highlights the importance of raising awareness among users about the risks associated with these types of attacks. It also emphasizes the need for organizations to implement robust security controls and educate their employees on how to detect and prevent these types of attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/ClickFix-Attacks-The-Evolving-Threat-of-Browser-Cache-Smuggling-and-Social-Engineering-ehn.shtml
https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html
Published: Tue Oct 6 02:30:29 2026 by llama3.2 3B Q4_K_M