{"id":2092,"date":"2026-10-07T07:18:03","date_gmt":"2026-10-07T00:18:03","guid":{"rendered":"https:\/\/vncybers.vn\/hieu-ve-clickfix-cache-smuggling-ma-doc-an-trong-bo-nho-dem-trinh-duyet\/"},"modified":"2026-10-07T07:18:03","modified_gmt":"2026-10-07T00:18:03","slug":"understanding-clickfix-cache-smuggling-malware-hidden-in-browser-cache","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/hieu-ve-clickfix-cache-smuggling-ma-doc-an-trong-bo-nho-dem-trinh-duyet\/","title":{"rendered":"Understanding ClickFix \u201cCache Smuggling\u201d: When Malware Hides in the Browser Cache"},"content":{"rendered":"<p>A new variation of <strong>ClickFix<\/strong> shows that social engineering attacks can incorporate very tightly into the legitimate mechanisms of browsers and Windows. Instead of asking the victim machine to directly download a detectable executable file, the compromised website silently inserted a piece of VBScript into the browser cache, disguised as a PNG image. Then, a fake verification guide tricks the user into opening the Run dialog and activating the content that is already on the device.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/10\/clickfix-cache-featured.webp\" alt=\"Illustration of a ClickFix campaign hiding malware in the browser cache\"\/><figcaption>The new ClickFix variant places the payload in the browser cache before tricking the user into activating it. Image: The Hacker News<\/figcaption><\/figure>\n<h2>What Is ClickFix and Why Does It Remain Effective?<\/h2>\n<p>ClickFix is a generic name for campaigns that build error messages, captcha, require a browser update, or a fake \u201cfix\u201d step. The website asks the user to copy an order, open Windows Run, PowerShell or Terminal, paste the command and press Enter. The victim itself becomes the execution link, helping the attacker avoid having to exploit a software vulnerability in the traditional way.<\/p>\n<p>The bait is convincing because it simulates familiar situations: the meeting doesn't work, the website needs verification, or the browser reports an error. The command running through the operating system's built-in tool may also look less suspicious than a downloaded executable file. However, a legitimate captcha does not require the user to open Run, PowerShell or Terminal to run the code.<\/p>\n<h2>How Does Cache Smuggling Change the Attack Chain?<\/h2>\n<p>According to Microsoft Threat Intelligence, compromised websites in the new campaign will preload the payload into the browser cache and make it look like a PNG file. When the user follows the ClickFix instructions, the pasted command does not need to contain the entire malicious code or a long file loading URL. It just needs to find the right item in the cache, copy that item to the temporary folder with the extension <code>.vbs<\/code> r\u1ed3i th\u1ef1c thi.<\/p>\n<p>This bypasses the 260-character length limit of the Windows Run dialog input. It also separates the point at which the payload is taken down from the point at which it is executed. The initial load can be seen as a normal web resource, while a user-run short command acts as a bridge to the stored malicious code.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/10\/hacker_code.jpg\" alt=\"A user working on a laptop and web browser\"\/><figcaption>ClickFix succeeds by persuading users to run commands themselves through trusted system tools. Real-world illustrative photo.<\/figcaption><\/figure>\n<h2>The Execution Chain from Browser Cache to Information Theft<\/h2>\n<p>In the Microsoft Observation form, VBScript calls <code>cmd.exe<\/code> to recursively browse files whose names start with <code>f_<\/code> in the browser profile folder, such as the Firefox profile below <code>%LOCALAPPDATA%<\/code>\u2219 Instead of finding a markup string in the content, the script compares the size of each file with the expected value. Size matching cache item copied to <code>%LOCALAPPDATA%\\Temp\\t.vbs<\/code> and run by <code>wscript.exe<\/code>; outputs and errors are both hidden.<\/p>\n<p>VBScript continues to collect machine information through Windows Management Instrumentation, retrieves a PowerShell script from an external server and launches it. The PowerShell layers then load more data, read, and execute in a hidden window. Last string loads assembly .NET into memory, inserts code into legitimate Windows process <code>timeout.exe<\/code> and targets browser and device credentials.<\/p>\n<p>The important point is that the browser cache does not turn itself into malicious code. The risk arises when the content controlled by the attacker is changed to an extension, moved to a new location, and executed by the script tool. So only clearing the cache can remove part of the original material but not enough if the payload is already running, has created a clinging mechanism, or has stolen information.<\/p>\n<h2>Defensive Signals to Monitor<\/h2>\n<p>Microsoft recommends that the defense team doesn't just hunt for file download events. Notable signals include an anomalous command in the history lock <code>RunMRU<\/code>, <code>wscript.exe<\/code> or PowerShell resulting from unfamiliar process sequences, scripts created in the Temp folder, browser profile queries, and recurring tasks that appear. Outbound connectivity from the Windows process, which rarely accesses the Internet, should also be investigated.<\/p>\n<p>PowerShell Script Block Logging, cloud-based web and network protection, and application control policies can provide an additional layer of observation. For enterprise environments, it is recommended to reconcile browser telemetry, process, registry, and DNS under the same timeline to avoid missing the chain of operations being broken down into several stages.<\/p>\n<h2>How Users and Organizations Can Reduce Risk<\/h2>\n<ol>\n<li>Train users to recognize simple principles: captcha or web verification steps never require pasting commands into Run, PowerShell or Terminal.<\/li>\n<li>Block or restrict VBScript, unsigned PowerShell and script interpreters in groups of users with no business needs.<\/li>\n<li>Enable web protection, application control, Script Block Logging, and transfer the log back to the centralized monitoring system.<\/li>\n<li>Monitor process relations, especially when the browser is followed by <code>cmd.exe<\/code>, <code>wscript.exe<\/code>, PowerShell, or the system process has an abnormal network connection.<\/li>\n<li>If in doubt the user has run the command, isolate the machine, preserve the log, review the retention mechanism, and reset the credentials from a clean device.<\/li>\n<li>Patch exploited websites and plugins to insert ClickFix primers; and check the integrity of server-side code and JavaScript served to visitors.<\/li>\n<\/ol>\n<h2>Lessons from Hiding Payloads in the Cache<\/h2>\n<p>Cache smuggling does not change the nature of ClickFix: the attack still needs to cause a human to commit a dangerous action. What is new is that the payload is pre-arranged in the legal storage area and the trigger is shortened, making the detection model based only on file downloads or a longer chain of command less effective.<\/p>\n<p>Good defense should combine user education with technical control and behavioral chain analysis. When a website requires an operation that goes beyond the browser to \u201cverify,\u201d it must be considered an initial sign of intrusion, not a typical error correction step.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from Microsoft Threat Intelligence and The Hacker News<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>M\u1ed9t bi\u1ebfn th\u1ec3 m\u1edbi c\u1ee7a ClickFix cho th\u1ea5y t\u1ea5n c\u00f4ng phi k\u1ef9 thu\u1eadt c\u00f3 th\u1ec3 k\u1ebft h\u1ee3p r\u1ea5t ch\u1eb7t v\u1edbi c\u01a1 ch\u1ebf h\u1ee3p ph\u00e1p c\u1ee7a tr\u00ecnh duy\u1ec7t v\u00e0 Windows. Thay v\u00ec y\u00eau c\u1ea7u m\u00e1y n\u1ea1n nh\u00e2n t\u1ea3i tr\u1ef1c ti\u1ebfp m\u1ed9t t\u1ec7p th\u1ef1c thi d\u1ec5 b\u1ecb ph\u00e1t hi\u1ec7n, website \u0111\u00e3 b\u1ecb x\u00e2m nh\u1eadp \u00e2m th\u1ea7m \u0111\u01b0a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2090,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[921,739,608,741,85,243],"class_list":["post-2092","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-kien-thuc","tag-browser-cache-smuggling","tag-clickfix","tag-microsoft-threat-intelligence","tag-powershell","tag-social-engineering","tag-vbscript"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2092","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=2092"}],"version-history":[{"count":0,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2092\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/2090"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=2092"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=2092"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=2092"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}