Microsoft Threat Intelligence (3 Oct): ClickFix via compromised sites pre-loads a VBScript payload into the browser cache disguised as a PNG — short Win+R command then hunts the cache, steals credentials, persists via Python task
Microsoft Threat Intelligence reported on 3 October 2026 a cluster of compromised websites that show a fake CAPTCHA or repair prompt telling visitors to open the Windows Run box, paste a copied command and press Enter. Unlike typical ClickFix lures, the page has already pre-fetched the main VBScript payload into the browser cache as a PNG-like file, so the pasted command can be short: it searches cache folders such as the Firefox profile for a file of an expected size, copies it to a temporary .vbs file and runs it through Windows Script Host with output hidden. The script gathers device details over WMI and pulls a PowerShell stage; later steps invoke .NET compilation tools, inject code into a legitimate Windows utility to steal browser-stored and device credentials, set the user's PowerShell execution policy to Bypass, unpack Python components and add a scheduled task that runs a Python payload windowlessly. Microsoft did not give victim numbers or name an operator. Wire: Cyber Security News 5 Oct.
- Product
- Windows endpoints — Run dialog, Windows Script Host, PowerShell; browser profile caches (e.g. Firefox)
- Versions
- n/a — social-engineering campaign, no CVE
- Exploited in Australia?
- unknown
- Patch to
- Tell users that a real CAPTCHA never asks them to paste anything into Run, Terminal or PowerShell. Hunt for RunMRU entries, wscript.exe or cmd.exe reading browser-cache files, new .vbs files in temp folders, PowerShell execution-policy changes and new scheduled tasks launching pythonw. Microsoft recommends cloud-delivered protection, web and network protection, application control and PowerShell script-block logging.
Primary: Microsoft Threat Intelligence on X — ClickFix with browser-cache pre-fetched payload (3 Oct 2026) · Cyber Security News — ClickFix fake CAPTCHA attack executes malware hidden inside browser cache (5 Oct 2026)
