Browser Cache Exploit Lets ClickFix Bypass Windows’ Run Box Limits

A fresh variant of ClickFix attacks has been uncovered that uses browser cache smuggling to sneak in malicious payloads without triggering standard security raise flags on Windows systems. By disguising scripts as image files pre-loaded into the browser cache, attackers avoid the usual restrictions tied to the Windows Run dialog, which traditionally cuts off commands longer than about 260 characters. This approach marks a new escalation in social engineering threats.

How the Cache Smuggling Technique Works

Instead of downloading malware outright, this variant has compromised websites pre-fetch script files into a user’s browser cache under the disguise of innocuous PNG images. When victims are later prompted to paste and run a command—typically through the “Run” dialog (Win + R)—those commands execute the cached content instead of reaching out to the internet for malware. This bypasses both character limits and many network-based defenses.

The staged payload usually manifests as a Visual Basic Script (VBScript): it searches the browser profile folder for files named with a certain pattern (for example, starting with “f_”) and matching a specific file size. When it finds one, it renames a size-matching cache entry to “t.vbs” and drops it into the Temp folder, then runs it via wscript.exe. Reports show the script suppresses any errors or output.

What Attackers Do Once Inside

After execution, this VBScript harvests system information via Windows Management Instrumentation (WMI) and proceeds to download additional payloads. Among them is an external PowerShell script which launches subsequent malware stages, including a downloaded file named “cab.dat.” That file gets executed in the background and leads to.NET-based code being injected into legitimate processes like timeout.exe. The ultimate goal: steal credentials—especially those tied to browsers—and persist inside the system.

This is not the first time such tactics have been seen. Over a year ago, a similar method was used to smuggle malicious payloads hidden within browser cache; even then, attackers used ZIP archives to stage infections.

ClickFix’s Evolution & Threat Landscape

ClickFix attacks rely heavily on social engineering. Commonly, victims are lured to fake error pages, fake CAPTCHA checks, or bogus browser updates. They’re then asked to copy-paste commands—often under the assumption of troubleshooting—and execute them in trusted utilities such as Windows Run, PowerShell, or macOS Terminal.

The rise of kits automating ClickFix campaigns has made these attacks even more widespread. Threat groups with nation-state support, including those aligned with North Korea and Russia, have reportedly used ClickFix to target businesses, financial institutions, and individuals.

Defensive Guidance

Microsoft and cybersecurity firms recommend multiple strategies to defend against this emerging threat. These include deploying cloud-based web and network protections, controlling app execution, and enabling detailed logging of PowerShell scripts. In addition, defenders are urged to monitor odd browser behavior, inspect the Windows Run dialog’s most recently used commands (RunMRU registry key), and track child processes of WScript and PowerShell.

There’s a clear consensus: no legitimate prompt should ask users to paste commands into system utilities like Run, Terminal, or PowerShell. Any such request should be treated as a possible entry point for an attack.

This update in ClickFix tactics matters because it shifts more power to the attacker in ways that are harder to detect. Smuggling payloads via cache and abusing character limits sidestep many traditional controls. As these techniques become normalized, defense strategies have to evolve accordingly. What to watch for next: smarter phishing with cache-aware content, better logging of RunMRU and download events, and tighter controls over browser-sourced code execution. Security teams should assume that a prompt to “fix” something isn’t always what it seems.