Microsoft Threat Intelligence reported a ClickFix attack that uses compromised websites and fake CAPTCHA or repair prompts to persuade visitors to execute attacker-supplied commands through the Windows Run dialog. The websites first cache a malicious VBScript payload disguised as a PNG, allowing the command to launch a locally staged script rather than visibly download it at execution time. The technique also circumvents the Run dialog’s approximately 260-character input limit. Subsequent stages use PowerShell, .NET compilation and in-memory loading, and code injection into timeout.exe to target browser-stored and device credentials. Persistence relies on unpacked Python components and a scheduled task invoking a windowless Python interpreter. Microsoft did not identify the operators or disclose a victim count.
Separate research illustrates the broader potential of ClickFix delivery. Expel analyzed a cache-smuggling chain, later identified as an Intrinsec red-team engagement, that repurposed a digitally signed Greenshot executable as a fake FortiClient compliance checker. A malicious plugin enabled DLL sideloading, decrypted shellcode from an icon file, established scheduled-task persistence, and used evasive execution techniques and disguised HTTPS command-and-control traffic; no final payload was observed. CloudSEK separately warned that attackers could potentially weaponize AI summarizers with CSS-based ClickFix attacks. These findings do not establish shared attribution with Microsoft’s reported activity. Defenders should prioritize application control, PowerShell logging, and monitoring of unusual browser-to-script execution, process injection, outbound connections, and scheduled tasks. Users should never execute commands supplied by CAPTCHA or verification prompts.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
Flare researcher Assaf Morag presented findings on a CrocoRat campaign using a fake verification page to trick victims into executing PowerShell. The initial command queried an attacker-controlled DNS server for TXT records containing further instructions, concealing the next-stage download chain from the copied command.
Researchers reported that CrocoRat attacker infrastructure became unusable in late September 2026. A takedown was suggested as a possible cause but was not confirmed.
CrowdStrike observed North Korea-aligned Stardust Chollima likely targeting a financial-services employee through a fake video-conferencing website. A fabricated technical problem prompted execution of a command that initiated a PowerShell and VBScript chain delivering the previously undocumented GeniexLoader and GeniexRAT families.
ReversingLabs reported that ClickFix campaigns exposed fewer conventional malware signals and rapidly rotated infrastructure, weakening detection based on historical indicators.
Expel documented a ClickFix browser-cache-smuggling chain whose second stage used a renamed, digitally signed Greenshot executable and a malicious plugin for DLL sideloading. The loader displayed a fake FortiClient compliance check, established scheduled-task persistence, and executed encrypted shellcode that contacted an HTTPS command-and-control server.
CloudSEK demonstrated how hidden HTML content and prompt injection could manipulate AI summarizers into presenting attacker-controlled ClickFix instructions. The proof of concept showed a potential route to ransomware delivery through manipulated summaries.
Microsoft Threat Intelligence disclosed activity across compromised websites that cached a VBScript payload disguised as a PNG and used fake CAPTCHA or repair prompts to induce its execution. Subsequent stages used PowerShell, in-memory .NET loading, injection into timeout.exe, and Python scheduled-task persistence to pursue browser and device credentials.
Russian state-sponsored Sandworm used ClickFix against suspected Ukrainian employees at organizations in France, the United States, and Canada. The lures induced PowerShell execution to download VBScript payloads, with delivery through compromised Ukrainian websites suspected.
CTM360 identified more than 3,000 actively compromised websites hosting fake pages in ClickFix attack chains delivering Vidar Stealer. The campaign exploited WordPress plugin vulnerabilities, including CVE-2026-6854, and used EtherHiding to rotate lure infrastructure through a blockchain-based mechanism.
Intrinsec stated that the cache-smuggling activity analyzed by Expel was part of its red team operations, changing the interpretation of the apparent malware campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourceinfosecurity-magazine.com
Open sourceflare.io
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceexpel.com
Open sourcecloudsek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.