ClickFix Evolves: Browser Cache Smuggling and Fake CAPTCHAs Bypass Windows Security

3 min read
Source: The Hacker News
ClickFix Evolves: Browser Cache Smuggling and Fake CAPTCHAs Bypass Windows Security
Photo: The Hacker News
TL;DR

A new ClickFix variant uses browser cache to bypass Windows Run character limits, while Ukrainian CERT-UA reports a surge in fake CAPTCHA attacks targeting Windows users via compromised sites.

Key points

  • Microsoft identified a ClickFix attack that pre-fetches malicious VBScript payloads into browser caches disguised as PNG files to evade the 260-character limit of the Windows Run dialog.
  • The payload executes via wscript.exe, harvests host data using WMI, and downloads further stages from external servers like 'cocojambo[.]us[.]com' and 'capsysnet[.]vg'.
  • Ukraine's CERT-UA detected over 100 compromised websites in September 2026 hosting fake Cloudflare verification pages that trick users into running commands via Win+R or PowerShell.
  • The malware, identified as LUNEXSTEALER, installs a browser extension disguised as 'Microsoft Office Word Editor' to steal credentials and grant remote access.
  • Attackers use blockchain networks like Polygon and Ethereum to dynamically update infrastructure, while CrowdStrike notes a 563% increase in fake CAPTCHA incidents in 2025.

Background

ClickFix has become a dominant initial access method, leveraging social engineering to bypass traditional security controls. Previous coverage noted the commoditization of these attacks through phishing kits and the use of AI summarization systems to deliver ransomware. The current developments represent a technical evolution, moving from simple command pasting to sophisticated cache smuggling and blockchain-controlled infrastructure, reflecting the increasing sophistication of nation-state and cybercriminal groups.

How outlets are covering it

Microsoft focuses on the technical evasion of Windows Run limits via browser cache, highlighting the stealth of the VBScript payload. CERT-UA and dev.ua emphasize the scale of the campaign in Ukraine, noting the use of compromised legitimate sites and fake Cloudflare verifications to target Windows users. While Microsoft details the multi-stage infection chain involving WMI and PowerShell, CERT-UA highlights the immediate impact on credential theft and remote access via malicious browser extensions. Both sources agree that user awareness and system restrictions on the Run dialog are critical defenses, but they differ in emphasis: Microsoft on technical detection, CERT-UA on user behavior and infrastructure blocking.

Why it matters

This highlights the growing sophistication of social engineering attacks that bypass traditional security measures by exploiting trusted system tools and user trust. The use of browser cache and blockchain infrastructure makes detection and mitigation more difficult, requiring organizations to move beyond download-based defenses to monitor suspicious browser activity and restrict user access to command-line tools.

What to watch

Expect increased scrutiny of browser cache contents and stricter policies on user access to the Run dialog and PowerShell. Defenders should monitor for WScript/PowerShell child processes and suspicious browser activity, while users must be educated to never execute commands from verification prompts. Organizations may implement more aggressive application control and PowerShell script-block logging to detect and prevent these attacks.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News