AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-1 of 1 results

DateProviderScoreSummary
06 Oct 2026, 1:22 PMThe Hacker News5.0 ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

Microsoft Threat Intelligence describes a ClickFix variant where compromised websites pre-fetch a VBScript payload into the victim's browser cache disguised as a PNG, so the command a user is tricked into pasting into the Windows Run dialog just executes content already on disk. This sidesteps the ~260-character truncation limit of the Run dialog that normally breaks long ClickFix one-liners. The staged VBScript enumerates files starting with "f_" in the Firefox profile folder (e.g. %LOCALAPPDATA%\Mozilla\Firefox\Profiles), copies the byte-length-matching cache entry to %LOCALAPPDATA%\Temp\t.vbs, runs it via wscript.exe, harvests host data over WMI, pulls v.ps1 from cocojambo[.]us[.]com/alfa, then cab.dat, loads .NET assemblies in memory and injects into timeout.exe, with a second in-memory stage from capsysnet[.]vg to target browser and device credentials.

Why: The attacker no longer needs a long paste, so the old heuristic of "the Run box cuts it off at ~260 chars" no longer protects anyone. If you or teammates copy-paste install or 'fix this error' commands from web pages, treat that as the primary infection path: the new IOCs to hunt are wscript.exe launched against %LOCALAPPDATA%\Temp\t.vbs and cache entries whose byte length matches a VBScript, plus outbound calls to cocojambo[.]us and capsysnet[.]vg. There is no Malaysian or Southeast Asian angle in this text; it applies to Windows users anywhere.

Top