Updated ClickFix Attack Caches Malware in Browser to Evade Windows Run Command Limits
A new ClickFix technique uses compromised sites to preload malicious scripts into the browser cache as fake PNG images, then triggers them via short pasted commands that bypass Windows Run’s 260‑character limit and start a multi‑stage malware chain.
Security researchers are describing a new evolution of the ClickFix attack chain that turns routine copy‑and‑paste troubleshooting into a path for malware.
In the latest variant, compromised websites preload malicious scripts into a visitor’s browser cache. Those scripts are served in a way that makes them look like PNG image files, blending into normal web content. When a user later copies a command from the page and pastes it into the Windows Run dialog or a terminal, that short snippet reaches into the cache and starts a multi‑stage malware deployment.
This approach works around the roughly 260‑character limit for commands executed through Windows Run. Instead of cramming an entire payload into a single, obviously suspicious line, the visible command can be brief while the real logic sits in cached resources fetched earlier by the browser.
For users, the sequence looks ordinary: visit a site, copy a command that claims to fix a problem, paste, and run. There’s no clear download prompt or warning. The exploit lives in how the browser cache and local command execution interact.
Helpdesk staff and administrators are particularly exposed because they often paste commands from online documentation or forum posts into elevated shells. If one of those sources has been compromised, attackers can gain code execution in high‑privilege environments, then bring down additional components, establish persistence, and move deeper through a network.
Researchers say this updated ClickFix method fits a broader pattern in which attackers rely less on obvious executable files and more on abusing normal user behavior and browser features. Because the critical payload sits in cached web content rather than a traditional download, many legacy security tools are less likely to see it.
In response, enterprise defenders are being urged to treat ad‑hoc copy‑paste instructions from the web as a potential attack surface and to steer staff toward vetted scripts and internal runbooks instead.
Security teams are watching for specific signs of this technique, such as servers that deliver script content under image file extensions, unusual cached resources on support‑themed domains, and command histories that show short loader commands preceding suspicious activity. Browser vendors and Microsoft may come under pressure to adjust how cached resources can be accessed and to harden the interaction between browsers, the Run dialog, and scripting environments on corporate systems.
Sources
- OSINT