Hackers hide VBScript payloads in browser caches via fake CAPTCHAs
A new ClickFix campaign places malicious scripts into browser caches disguised as images to bypass Windows command length limits.
FTMQ Security, written by our newsroom0 views

Compromised websites are using a novel ClickFix attack to trick users into executing malicious VBScript files pre-fetched into their browser cache. InfoSecurity Magazine and The Hacker News both report that Microsoft Threat Intelligence observed the social engineering campaign targeting web visitors. Microsoft posted details of the activity on X on October 3. [1][2]
ClickFix attacks use fake verification steps, such as a malicious CAPTCHA pop-up, to manipulate users into opening the Windows Run dialog, pasting clipboard content, and hitting Enter. InfoSecurity Magazine and The Hacker News report that this campaign pre-fetches a VBScript payload disguised as a PNG image file into the browser cache before prompting the user. This staging tactic allows attackers to bypass length limits in the Windows Run dialog. [1][2]
A web cache is a system implemented client-side or server-side to optimize web browsing by storing multimedia and files locally. In this attack chain, executing the cached script launches malware designed to target user credentials, according to The Hacker News. [2][7]
In short
- ClickFix campaigns trick users into running clipboard commands via fake CAPTCHA pop-ups.
- Attackers pre-fetch VBScript payloads disguised as PNG images into the browser cache.
- Microsoft Threat Intelligence highlighted the technique in a post on X on October 3.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]ClickFix Attack Hides VBScript Payload in Browser CacheInfoSecurity Magazine, 1d ago (the report this story comes from)
- [2]ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run LimitsThe Hacker News, 1d ago
- [3]ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run LimitsThe Hacker News, 1d ago
- [4]ClickFix: Hides Payloads in the Browser CacheSecNews.gr, 1d ago
- [5]ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser CacheCyberSecurityNews, 2d ago
Background
- [6]Timeline of malware on Wikipedia
- [7]Web cache on Wikipedia
Our newsroom writes these reports with the help of software, from the 7 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
More in Data Breaches
- OT Coalition Urges CISA to Mandate Security Standards for Federal Systems6m ago
- New Linux Backdoors Target Telecom Appliances in South Korea and Taiwan2d ago
- ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes2d ago
- Microsoft Warns AI Compresses Attack Lifecycle from Days to Minutes3d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.