Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-06 · updated: 2026-10-06 · tags: [incident, global] · confidence: high · severity: low · affected_sectors: [global] · au_impact: false

Microsoft Threat Intelligence detailed a ClickFix campaign that hides a script payload in victims' browser caches disguised as a PNG image file, then finds it again by file size alone — a refinement of the "cache smuggling" technique security researcher Marcus Hutchins described in October 2025. In the campaign, a cluster of compromised websites pre-fetched the payload into visitors' caches; the ClickFix lure then posed as a Cloudflare human-verification check, telling victims to open the Windows Run dialog, paste clipboard contents and press Enter — loading and executing (via WScript/PowerShell) a payload that was "already on the device, loaded, and ready to be executed." Unlike earlier cache-smuggling variants that searched for a content marker, this campaign identifies the hidden payload purely by comparing file sizes. Microsoft advises defenders to hunt across browser activity, Run-dialog history, WScript and PowerShell child processes and scheduled tasks rather than relying on download events, since the technique avoids any conventional file download at the moment of execution. Why it matters: file-size-based cache staging defeats both download monitoring and naive content scanning, making ClickFix-style social engineering harder to detect at the endpoint.

Attribute Detail
Sector Global (Macro)
Date 2026-10-06
Source iTnews
Reliability Tier 3