A new ClickFix campaign is turning a web safety check into a route for malware. The campaign starts after a victim reaches an altered website, where they see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter.
The instruction looks simple, but it makes the victim run the attacker’s command. The main script is placed on the computer before that step, hiding in the browser cache rather than arriving as an obvious download. Microsoft Threat Intelligence identified the activity in a cluster of compromised websites.[/subscribe_to_unlock_form]
A new ClickFix campaign is turning a web safety check into a route for malware. The campaign starts after a victim reaches an altered website, where they see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter.
The instruction looks simple, but it makes the victim run the attacker’s command. The main script is placed on the computer before that step, hiding in the browser cache rather than arriving as an obvious download. Microsoft Threat Intelligence identified the activity in a cluster of compromised websites.[emaillocker id="1283"]
The attack starts after a victim reaches an altered website. A fake verification or repair panel asks them to use Win+R, paste material from the clipboard, and run it. Behind the page, the VBScript payload has already been stored in the browser profile cache as a PNG-like resource.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1059.005 | Command and Scripting Interpreter | Visual Basic |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Execution | E1204 | User Execution |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Command & Control | E1105 | Ingress Tool Transfer |
| Command & Control | B0030 | C2 Communication |
| Discovery | E1083 | File and Directory Discovery |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
The following reports contain further technical details:
[/emaillocker]