ClickFix Attack Bypasses Windows Limits via Browser Cache Smuggling
A new ClickFix variant hides malicious payloads in browser caches by disguising them as image files. This technique bypasses traditional execution limits on Windows systems.
TL;DR
- New ClickFix attacks use compromised sites to cache malicious scripts disguised as PNG files.
- The method avoids direct downloads, evading Windows Defender Application Control restrictions.
- Microsoft Threat Intelligence warns that users unknowingly execute cached payloads through social engineering.
- Organizations should monitor browser cache behaviors and enforce strict content-type policies.
- Security teams need updated detection rules to identify obfuscated payloads in web caches.
Cybercriminals continue evolving their tactics to evade modern defenses, and a newly observed strain of ClickFix attack is taking an unusual route—through the browser’s own cache. By leveraging compromised websites, attackers are now delivering malicious payloads that appear as harmless PNG files but are actually executable scripts stored locally.
This approach circumvents traditional safeguards such as Windows Defender Application Control (WDAC), which typically restricts the execution of unsigned or unauthorized binaries. Because the payload resides within the browser's trusted cache rather than being directly downloaded, it presents a stealthy vector for exploitation.
How It Works
- Compromised websites prefetch JavaScript payloads and store them in the browser cache under伪装文件扩展名 like .png.
- When users visit these pages, the malicious script loads silently into the cache without triggering download warnings.
- Subsequent user interaction—such as clicking a link—triggers execution of the cached payload via HTML smuggling techniques.
- Because the payload originates from the local cache, it can bypass WDAC policies that block external executable downloads.
Defense Recommendations
- Implement Content Security Policy (CSP) headers to restrict script sources and execution contexts.
- Monitor network requests for unexpected resource types masquerading as common image formats.
- Use browser security extensions or enterprise policies to disable unnecessary caching of executable MIME types.
- Educate users about risks associated with visiting untrusted websites, even if they appear benign.
- Deploy behavioral analytics tools capable of detecting anomalous script execution patterns originating from cached resources.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.