Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClickFix compromised-website browser-cache campaign

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

The ClickFix campaign is using compromised websites to pre-stage a VBScript payload in the browser cache, pushing visitors into running attacker code through Windows Run and increasing the risk of credential theft. Microsoft Threat Intelligence observed the activity on October 3, 2026 and said a fake CAPTCHA prompt was used to make users paste and execute a command. The chain avoids a fresh download at execution time by launching a file that is already on disk. That blend of social engineering and local staging makes the payload harder to detect and expands the chance of follow-on access.

Related Happenings

Psychedelic Stealer / LunexStealer MaaS infostealer deployment

Malware Activity
H score29 First: 26.09.2026 21:22 Last: 26.09.2026 21:22 Sources 1

About this happening: Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while kee...

ChainScript RAT delivered via ClickFix-like lures

Malware Activity
H score23 First: 21.09.2026 11:39 Last: 21.09.2026 11:39 Sources 1

About this happening: The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...

UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets

Campaign
H score24 First: 19.07.2026 16:30 Last: 19.07.2026 16:30 Sources 1

About this happening: Sandworm-linked UAC-0145 is running a ClickFix campaign that uses compromised websites and fake CAPTCHA lures to push Ukrainian targets into executing atta...

ACR Stealer enterprise infostealer surge

Malware Activity
H score29 First: 18.07.2026 17:17 Last: 18.07.2026 17:17 Sources 1

About this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....

ClickFix-based TELEPUZ distribution campaign

Campaign
H score35 First: 16.07.2026 15:50 Last: 16.07.2026 15:50 Sources 1

About this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...

Timeline

  1. 06.10.2026 18:00 1 articles · 1h ago

    Fake CAPTCHA drives Windows Run execution from cached VBScript

    Exploitation Observed

    A fake CAPTCHA pop-up told visitors to open Run, paste a command from the clipboard and press Enter, while cmd.exe searched the browser profile folder for cached files beginning with "f_" and launched the matching payload from disk as .vbs.

    Show sources
  2. 06.10.2026 18:00 1 articles · 1h ago

    VBScript collects host data, injects timeout.exe, and installs a Python scheduled task

    Technical Analysis Update

    The VBScript gathered host details with Windows Management Instrumentation (WMI), fetched a PowerShell script with the execution policy bypassed, injected later-stage code into timeout.exe on the affected device for credential theft from browsers and devices, and then unpacked Python with tar.exe before creating a scheduled task that ran a Python payload through pythonw.exe.

    Show sources
  3. 03.10.2026 03:00 2 articles · 3d ago

    Compromised websites preload VBScript into browser cache for ClickFix victims

    Initial Disclosure

    Microsoft Threat Intelligence said a cluster of compromised websites was steering visitors into a ClickFix campaign on October 3, with the sites preloading a VBScript payload into the browser cache so the script was already on the device before execution via Windows Run.

    Show sources