AI Weekly Malaysia

Back to items Summaries

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

ID
32163
Status
summarized
Published
06 Oct 2026, 1:22 PM
Fetched
06 Oct 2026, 3:15 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.0
Created
06 Oct 2026, 3:16 PM
Tags
Audience
developersvibe_coders

What happened

Microsoft Threat Intelligence describes a ClickFix variant where compromised websites pre-fetch a VBScript payload into the victim's browser cache disguised as a PNG, so the command a user is tricked into pasting into the Windows Run dialog just executes content already on disk. This sidesteps the ~260-character truncation limit of the Run dialog that normally breaks long ClickFix one-liners. The staged VBScript enumerates files starting with "f_" in the Firefox profile folder (e.g. %LOCALAPPDATA%\Mozilla\Firefox\Profiles), copies the byte-length-matching cache entry to %LOCALAPPDATA%\Temp\t.vbs, runs it via wscript.exe, harvests host data over WMI, pulls v.ps1 from cocojambo[.]us[.]com/alfa, then cab.dat, loads .NET assemblies in memory and injects into timeout.exe, with a second in-memory stage from capsysnet[.]vg to target browser and device credentials.

Why it matters

The attacker no longer needs a long paste, so the old heuristic of "the Run box cuts it off at ~260 chars" no longer protects anyone. If you or teammates copy-paste install or 'fix this error' commands from web pages, treat that as the primary infection path: the new IOCs to hunt are wscript.exe launched against %LOCALAPPDATA%\Temp\t.vbs and cache entries whose byte length matches a VBScript, plus outbound calls to cocojambo[.]us and capsysnet[.]vg. There is no Malaysian or Southeast Asian angle in this text; it applies to Windows users anywhere.

Discussion angle

The payload hides in browser cache as a PNG rather than being downloaded — walk through how a file-length match on a cache entry becomes a detection rule, and debate whether 'never paste commands from a website' is teachable to non-technical teammates or whether it needs tooling/allowlisting instead.

Top