Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Fake Cloudflare verification box with Win+R, Ctrl+V and Enter steps above a Windows Run dialog, with the cmd for /r command that searches the Firefox profile for f_ files of 33433 bytes.
Screenshot: Microsoft Threat Intelligence, a fake Cloudflare check telling the visitor to paste a command into Windows Run that copies a cached file to t.vbs and runs it, Oct 3, 2026 (fair use).

Detection

Microsoft Warns ClickFix Lures Now Hide Their Payload in the Browser Cache

Microsoft Threat Intelligence said on October 3 that compromised websites are pre-fetching a VBScript payload into visitors' browser caches disguised as a PNG file, so the ClickFix command a victim pastes into Windows Run only has to find and launch it. Huntress, separately, described killing ClickFix chains on the endpoint before its SOC saw the alert.

Ava Okello, DetectionLondon5 min read

LONDON - A ClickFix campaign tracked by Microsoft no longer needs the victim's pasted command to download anything. Compromised websites quietly pre-fetch a script into the visitor's browser cache, disguised as an image, and the command the victim is talked into pasting into the Windows Run dialog only has to find that file and launch it. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," Microsoft Threat Intelligence said in a post on X on October 3. For security operations teams, the shift removes one of the easier tells in a ClickFix alert: a URL or download cradle sitting in the pasted command line.

The staged payload is a VBScript file, according to Microsoft's account as reported by The Hacker News. The pasted command runs cmd.exe to walk the browser's profile folder, such as %LOCALAPPDATA%\Mozilla\Firefox\Profiles, looking for cache files whose names begin with "f_". "It compares each file's byte length with an expected value," Microsoft wrote. "Rather than searching for a marker within the contents like previous attacks, it copies a size-matching cache entry to %LOCALAPPDATA%\Temp\t.vbs, giving the cached payload a VBScript extension, then executes it with wscript.exe. Copy output and errors are suppressed. The expected size varies across variants." In the lure Microsoft posted, a fake Cloudflare check tells the visitor to press Win+R, paste and press Enter, and the command looks for a file of 33,433 bytes. The Hacker News noted that the Run dialog truncates input longer than about 260 characters, a limit the cached script sidesteps.

What follows is a credential theft chain, Microsoft said. The VBScript collects host details through Windows Management Instrumentation and fetches a PowerShell script, v.ps1, from cocojambo[.]us[.]com/alfa, which leads to a further download, cab.dat, whose contents run in a hidden window. .NET assemblies loaded into memory then inject code into a newly launched copy of the legitimate timeout.exe utility to go after browser and device credentials, and the injected process starts PowerShell to pull another in-memory stage from capsysnet[.]vg and connect out to ciliabula[.]cc.

The technique is not new, but the matching method is. In October 2025, Marcus Hutchins, writing for Expel, described a lure posing as a Fortinet VPN compliance checker that served a ZIP archive labeled as a JPEG image, let Chrome cache it, and used PowerShell to copy the cache folder and carve the archive out from between two marker strings, bTgQcBpv and mX6o0lBw. The Hacker News reported that the activity was later identified as a red team engagement by Intrinsec. Expel warned then that "any tools scanning downloaded files or looking for PowerShell scripts performing web requests wouldn't detect this behavior." Microsoft's variant drops the markers and picks the file by name prefix and size.

HxD hex editor view of a cached file beginning with bTgQcBpv then PK and the name FortiClientComplianceChecker.exe.
Screenshot: Expel, the fake JPEG served by a 2025 cache smuggling lure opens with the marker bTgQcBpv followed by a ZIP header, Oct 8, 2025 (fair use).The cached file opens with the marker bTgQcBpv and then a ZIP header.

On October 5, Huntress published a detection engineering account that addresses the other half of the problem: speed. "ClickFix chains move from stage one to stage two to stage three in mere seconds," wrote Shivangi Pandey and Jonathan Semon. Huntress said it reviewed 8,332 ClickFix-related items from a 60-day window and found that the tell sat at the root of the process chain or right next to it, in the command the user pasted. Because a command launched from the Run dialog always has explorer.exe as its parent, "the rule shape became: match the command line, gate it behind the parent." Those rules run inside the Huntress EDR agent, which kills the chain in under a second and alerts the company's SOC at the same time.

Huntress described one incident at a mining and natural resources company. The user pasted a command that used caret characters to disguise the words start and finger, and relied on finger.exe, a utility that ships with Windows, to fetch text from a remote host and run it. Four processes were spawned and killed inside 1.25 seconds. The user tried five more times, six pastes between 18:07 and 18:53, and each was killed. The alert reached the Huntress SOC roughly 70 seconds after the first kill. "The chain was already dead before a human knew it existed," the company wrote.

Huntress EDR alert panel titled ClickFix Initial Access Execution, Mode Enforce, five Process was killed badges and a caret-obfuscated cmd.exe command line.
Screenshot: Huntress, an enforce-mode ClickFix rule hit that killed five processes spawned by an obfuscated finger command, Oct 5, 2026 (fair use).The enforce-mode rule killed the processes spawned by the pasted command.

Huntress is describing its own product, and it listed the limits. Rules start in audit mode and are promoted to enforcement only after clearing what the company called "a strict efficacy bar of 99% accurate." They cover Windows only. Some variants use start to detach the follow-on process, which let payload retrieval continue after a successful kill until Huntress added a second rule that matches the parent's command line and kills both. "This is disruption, not prevention," the authors wrote. Huntress did not say whether its rules catch the cache-staged variant Microsoft described.

Huntress EDR alert panel for the Child Process Kill rule in Enforce mode showing cmd.exe PID 20852 killed, username and SID blurred.
Screenshot: Huntress, the second rule that kills the child cmd.exe left running after a detached launcher exits, Oct 5, 2026 (fair use).A second rule kills the child cmd.exe after a detached launcher exits.

For SOC teams writing their own detections, the sources point to the same places. Microsoft urged defenders to look beyond download events and hunt for suspicious browser activity, the RunMRU registry key that records commands typed into the Run dialog, child processes of WScript and PowerShell, and new scheduled tasks, and it recommended PowerShell script-block logging, application control and network protection. Expel advised alerting on unexpected processes touching the browser cache. In practice that means cmd.exe launched by explorer.exe and enumerating a browser profile, a .vbs file written to Temp and run by wscript.exe, and timeout.exe launching PowerShell. Because the expected file size changes between variants, a rule keyed to one value will age quickly. "A CAPTCHA should not ask users to run code," Microsoft said.

Sources:


Ava Okello covers detection engineering, EDR telemetry, and SOC hunting for SOCtember from London.

Related stories

Detection desk