ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
Microsoft Threat Intelligence has detailed a new ClickFix variant in which compromised websites pre-fetch a malicious script into the browser cache disguised as a PNG file, then trick users into executing it. The technique bypasses Windows restrictions on running remote payloads.
- Attack uses browser cache instead of downloading a remote file
- Script is disguised as a PNG and pre-fetched by the site
- Method bypasses Windows limits on running remote payloads
- Finding reported by Microsoft Threat Intelligence
Read next
Security