A variant of the ClickFix social-engineering playbook is doing away with remote payload delivery altogether. Rather than asking victims to download malware, attackers are pre-loading it into the browser's own cache, disguised as an image file — and then coaxing the user into running it locally.

Microsoft Threat Intelligence disclosed the technique in a post on the X social media platform, which The Hacker News reported on 6 October. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the team wrote.

The campaigns using this variant leverage compromised websites to stage the payload. When a user lands on a booby-trapped page, the site silently requests a resource that the browser dutifully stores in its cache — but that resource is really a script, not an image. The attacker then tells the user to paste a command into the Windows Run dialog (Win+R), a ClickFix staple that reframes malware execution as a routine troubleshooting step the victim performs themselves.

Why it matters

Because the payload is already sitting on the victim's machine, the execution step generates almost none of the network traffic defenders have historically keyed on. There is no fresh download to block, no malware URL to sinkhole, no command-and-control beacon firing at the moment of execution — the transfer from attacker-controlled server to victim disk happened long before the user ran anything. Network telemetry that once provided the first warning of an attack now sees, at best, a local process reading a file.

ClickFix-style attacks gained traction precisely because they hijack the victim's trust in their own machine: the user isn't installing anything, they're "fixing" a browser problem. This new variant raises the stakes by turning one of the most trusted locations on a Windows box — the browser cache — into pre-staged attacker-controlled storage, and by widening the blast radius of any single compromised website, since the compromise itself is the delivery mechanism.

Microsoft has not publicly attributed the campaigns using this variant, disclosed how many sites are affected, or stated which browsers' cache directories the technique targets. Those gaps matter for defenders, because the precise cache path and file-naming behaviour determine what detection content to write.

Practical mitigations

For Windows-centric estates, the defences are less about patching and more about script hygiene:

  • Treat any webpage that instructs users to paste a command into the Run dialog or a terminal as hostile by default. It is almost always a social-engineering technique, not a support step.
  • Constrain PowerShell, other scripting interpreters and the Run dialog through Group Policy or MDM wherever business use allows.
  • Extend detection coverage beyond downloads and %TEMP% to script execution from browser cache and other browser data directories.
  • Alert on scripts executing from cache directories, particularly files carrying non-script extensions such as .png.
  • Audit browser prefetch and caching hardening settings, and treat the cache directory as untrusted storage rather than benign residue.

The campaign's scope remains undisclosed. Organisations should assume the technique is already circulating in the wild, and that standard ClickFix awareness guidance still applies — the payload has simply moved closer to the victim.


ClickFix 社交工程攻擊手法的其中一個變種,如今已完全放棄從遠端伺服器交付 payload。攻擊者不再要求受害者下載惡意軟件,而是事先將其預載入瀏覽器本身的快取之中,偽裝成一個影像檔案——然後誘導用戶在本地執行。

Microsoft Threat Intelligence 在社交媒體平台 X 的帖文中披露了這項手法,《The Hacker News》於 10 月 6 日作出報道。該團隊表示:「與一般攻擊模式下載及執行遠端 payload 的做法不同,在這次攻擊中,網站會將一個腳本 payload 以 PNG 檔案的偽裝,預先抓取到瀏覽器快取之內。」

使用此變種的攻擊行動,是利用已被入侵的網站來部署 payload。當用戶登入到被動了手腳的頁面時,網站會靜默地向瀏覽器請求某項資源,而瀏覽器則按部就班地將其儲存於快取之中——但該資源實際上是一個腳本,而非影像。攻擊者其後便指示用戶把指令貼入 Windows 的執行視窗(Win+R),這正是 ClickFix 的慣用招式:將惡意軟件執行重新包裝成受害者自行完成的例行疑難排解步驟。

為何值得關注

由於 payload 已經存在於受害者電腦之上,執行階段幾乎不會產生任何防禦人員一直以來依賴追蹤的網絡流量。沒有新的下載可供攔截,沒有惡意網址可供 sinkhole,執行的一刻也沒有 command-and-control 信號發出——由攻擊者控制的伺服器傳輸至受害者磁碟的過程,早在用戶執行任何東西之前便已完成。曾經作為攻擊首個預警的網絡遙測數據,如今頂多只會看到一個本地進程在讀取檔案。

ClickFix 類型的攻擊之所以蔓延,正是因為它劫持了受害者對自己電腦的信任:用戶並非在安裝任何東西,而只是在「修復」一個瀏覽器問題。這個新變種將風險推向更高層次——它把 Windows 電腦上最受信任的位置之一,即瀏覽器快取,變成攻擊者預先部署的控制儲存空間,同時擴大了任何單一被入侵網站的波及範圍,因為入侵本身即是交付機制。

微軟尚未公開指認使用此變種的攻擊行動,沒有披露受影響網站的數目,亦沒有說明這項手法針對哪些瀏覽器的快取目錄。這些資訊缺口對防禦人員至關重要,因為確切的快取路徑及檔案命名行為,決定了需要撰寫什麼檢測規則。

實用緩解措施

對於以 Windows 為核心的系統環境,防禦重點不在於打補丁,而在於腳本管理:

  • 預設應將任何指示用戶把指令貼入執行視窗或終端機的網頁視為敵意內容。這幾乎總是社交工程手法,而非支援步驟。
  • 在業務用途許可的範圍內,透過 Group Policy 或 MDM 管控 PowerShell、其他腳本解釋器及執行視窗。
  • 將檢測範圍由下載及 %TEMP% 擴展至從瀏覽器快取及其他瀏覽器資料目錄執行的腳本。
  • 對從快取目錄執行的腳本發出警示,尤其注意帶有非腳本副檔名(例如 .png)的檔案。
  • 檢視瀏覽器預抓取及快取加固設定,並將快取目錄視為不可信儲存空間,而非無害的殘留資料。

該攻擊行動的規模至今仍未公開。各機構應假設這項手法已在現實中流通,並繼續適用既有的 ClickFix 安全意識培訓指引——payload 只不過是移動到更接近受害者的位置。

新聞來源 / Original News Source