ClickFix Social Engineering Attacks Evolve to Hide Payloads in Browser Caches
Hackers are updating ClickFix social engineering attacks by pre-fetching malicious payloads into browser caches and hiding data within DNS TXT records to bypass security controls.
FTMQ Security, written by our newsroom0 views

Hackers are using updated ClickFix attack techniques to hide malicious payloads in browser caches and domain name system text records, according to reports from Dark Reading, Cisco Talos, and The Hacker News. The revised tactics allow attackers to evade early detection and bypass standard Windows execution limits. [1][2][3][4]
The Hacker News reported that compromised websites trick users into executing malicious scripts that are pre-fetched directly into the browser cache. These scripts are frequently disguised as image files, such as PNG files, rather than downloading files using typical remote retrieval patterns. [3]
Microsoft observed ClickFix campaigns using browser cache smuggling to execute cached VBScript files, according to The Hacker News. This technique launches a malware chain designed to target user credentials. [3]
Dark Reading reported that attackers are also storing hidden payloads inside DNS TXT records and leveraging browser cache pre-fetching. These mechanisms make it significantly harder for security teams to identify the early stages of an attack chain. [1]
In short
- ClickFix attacks are pre-fetching malicious payloads disguised as PNG files into browser caches.
- Microsoft detected campaigns using cached VBScript to launch credential-targeting malware.
- Attackers are hiding malicious payloads inside DNS TXT records to avoid early detection.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]ClickFix Attacks Evolve to Better Hide Malicious PayloadsDark Reading, 1d ago (the report this story comes from)
- [2]Cisco Talos Highlights How Clickfix Attacks Are Exploiting Trusted Online ServicesMenafn, 1d ago
- [3]ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run LimitsThe Hacker News, 1d ago
- [4]ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run LimitsThe Hacker News, 1d ago
Background
- [5]Polymorphic code on Wikipedia
- [6]Wikipedia on Wikipedia
Our newsroom writes these reports with the help of software, from the 6 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- Hackers hide VBScript payloads in browser caches via fake CAPTCHAsData Breaches, 1d ago
More in Top Stories
- Attackers hijack top level domains to obtain unauthorized Google security certificates6m ago
- Discord security bot Double Counter breached exposing user email addresses6m ago
- FBI warns ongoing FortiBleed attacks target Fortinet VPNs and lock out administrators7m ago
- MonsterCloud owner charged over secret ransomware payments7m ago
- Ransomware group BYOD claims data breach exposing Trump Mobile subscriber records7m ago
- FBI removes Accenture contractor following Oracle PeopleSoft data breach1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.