Skip to the stories
Thursday, 8 October 2026
Saved

Next edition

10:40

Headlines

Data Breaches

Hackers hide VBScript payloads in browser caches via fake CAPTCHAs

A new ClickFix campaign places malicious scripts into browser caches disguised as images to bypass Windows command length limits.

FTMQ Security, written by our newsroom0 views

Share
Picture: InfoSecurity Magazine
Watch: this report in under a minute. The presenter and voice are AI-generated. More video reports

Compromised websites are using a novel ClickFix attack to trick users into executing malicious VBScript files pre-fetched into their browser cache. InfoSecurity Magazine and The Hacker News both report that Microsoft Threat Intelligence observed the social engineering campaign targeting web visitors. Microsoft posted details of the activity on X on October 3. [1][2]

ClickFix attacks use fake verification steps, such as a malicious CAPTCHA pop-up, to manipulate users into opening the Windows Run dialog, pasting clipboard content, and hitting Enter. InfoSecurity Magazine and The Hacker News report that this campaign pre-fetches a VBScript payload disguised as a PNG image file into the browser cache before prompting the user. This staging tactic allows attackers to bypass length limits in the Windows Run dialog. [1][2]

A web cache is a system implemented client-side or server-side to optimize web browsing by storing multimedia and files locally. In this attack chain, executing the cached script launches malware designed to target user credentials, according to The Hacker News. [2][7]

Share

In short

  • ClickFix campaigns trick users into running clipboard commands via fake CAPTCHA pop-ups.
  • Attackers pre-fetch VBScript payloads disguised as PNG images into the browser cache.
  • Microsoft Threat Intelligence highlighted the technique in a post on X on October 3.

Sources

Every paragraph above points to the numbered items it rests on. Read the originals here.

  1. [1]ClickFix Attack Hides VBScript Payload in Browser CacheInfoSecurity Magazine, 1d ago (the report this story comes from)
  2. [2]ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run LimitsThe Hacker News, 1d ago
  3. [3]ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run LimitsThe Hacker News, 1d ago
  4. [4]ClickFix: Hides Payloads in the Browser CacheSecNews.gr, 1d ago
  5. [5]ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser CacheCyberSecurityNews, 2d ago

Background

  1. [6]Timeline of malware on Wikipedia
  2. [7]Web cache on Wikipedia

Our newsroom writes these reports with the help of software, from the 7 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.

Earlier reports of ours on the same people and subjects.

More in Data Breaches

Get the day in one email

Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments

Loading

Join the conversation

Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.

Already on the list? Enter the same address and we will send a sign-in link.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.