ClickFix compromised-website browser-cache campaign
Campaign
Summary
Hide ▲
Show ▼
The ClickFix campaign is using compromised websites to pre-stage a VBScript payload in the browser cache, pushing visitors into running attacker code through Windows Run and increasing the risk of credential theft. Microsoft Threat Intelligence observed the activity on October 3, 2026 and said a fake CAPTCHA prompt was used to make users paste and execute a command. The chain avoids a fresh download at execution time by launching a file that is already on disk. That blend of social engineering and local staging makes the payload harder to detect and expands the chance of follow-on access.
Related Happenings
Psychedelic Stealer / LunexStealer MaaS infostealer deployment
Malware Activity
H score29
First: 26.09.2026 21:22
Last: 26.09.2026 21:22
Sources 1
About this happening:
Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while kee...
Psychedelic Stealer / LunexStealer MaaS infostealer deployment
Malware ActivityAbout this happening: Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while kee...
ChainScript RAT delivered via ClickFix-like lures
Malware Activity
H score23
First: 21.09.2026 11:39
Last: 21.09.2026 11:39
Sources 1
About this happening:
The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...
ChainScript RAT delivered via ClickFix-like lures
Malware ActivityAbout this happening: The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
Campaign
H score24
First: 19.07.2026 16:30
Last: 19.07.2026 16:30
Sources 1
About this happening:
Sandworm-linked UAC-0145 is running a ClickFix campaign that uses compromised websites and fake CAPTCHA lures to push Ukrainian targets into executing atta...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
CampaignAbout this happening: Sandworm-linked UAC-0145 is running a ClickFix campaign that uses compromised websites and fake CAPTCHA lures to push Ukrainian targets into executing atta...
ACR Stealer enterprise infostealer surge
Malware Activity
H score29
First: 18.07.2026 17:17
Last: 18.07.2026 17:17
Sources 1
About this happening:
ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ACR Stealer enterprise infostealer surge
Malware ActivityAbout this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ClickFix-based TELEPUZ distribution campaign
Campaign
H score35
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickFix-based TELEPUZ distribution campaign
CampaignAbout this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
Timeline
-
06.10.2026 18:00 1 articles · 1h ago
Fake CAPTCHA drives Windows Run execution from cached VBScript
Exploitation ObservedA fake CAPTCHA pop-up told visitors to open Run, paste a command from the clipboard and press Enter, while cmd.exe searched the browser profile folder for cached files beginning with "f_" and launched the matching payload from disk as .vbs.
Show sources
- ClickFix Attack Hides VBScript Payload in Browser Cache — www.infosecurity-magazine.com — 06.10.2026 18:00
-
06.10.2026 18:00 1 articles · 1h ago
VBScript collects host data, injects timeout.exe, and installs a Python scheduled task
Technical Analysis UpdateThe VBScript gathered host details with Windows Management Instrumentation (WMI), fetched a PowerShell script with the execution policy bypassed, injected later-stage code into timeout.exe on the affected device for credential theft from browsers and devices, and then unpacked Python with tar.exe before creating a scheduled task that ran a Python payload through pythonw.exe.
Show sources
- ClickFix Attack Hides VBScript Payload in Browser Cache — www.infosecurity-magazine.com — 06.10.2026 18:00
-
03.10.2026 03:00 2 articles · 3d ago
Compromised websites preload VBScript into browser cache for ClickFix victims
Initial DisclosureMicrosoft Threat Intelligence said a cluster of compromised websites was steering visitors into a ClickFix campaign on October 3, with the sites preloading a VBScript payload into the browser cache so the script was already on the device before execution via Windows Run.
Show sources
- ClickFix Attack Hides VBScript Payload in Browser Cache — www.infosecurity-magazine.com — 06.10.2026 18:00
- ClickFix Attack Hides VBScript Payload in Browser Cache — www.infosecurity-magazine.com — 06.10.2026 18:00