Skip to content
Brief Security & Trust ·

ClickFix attack hides a script as a fake image, then finds it by file size

Microsoft says hacked sites plant the script in browser caches, and a pasted command finds it by size.

In brief
  • Microsoft says hacked websites left a script in visitors' caches as a fake PNG image. A fake Cloudflare check then got users to run a command that finds it.
  • Microsoft did not name the attackers, say how many sites were hacked, or say which credential stealer was used.

iTnews reported on 6 October 2026 that Microsoft Threat Intelligence found a new ClickFix campaign. ClickFix tricks people into running an attacker's command themselves. Hacked websites quietly left a script in visitors' browser caches, labelled as a PNG image. A fake Cloudflare human check then told users to paste a command into the Windows Run box.

Microsoft said the command hunts through Firefox profile folders for files with an f_ prefix and picks the one with the expected size. It saves that file in Temp as a VBScript and starts it. Expel's Marcus Hutchins described cache smuggling in October 2025, when attackers searched for a hidden marker inside files. Microsoft did not name the attackers, say how many sites were hacked, or say which credential stealer was used.

In our reading, the file arrives during an ordinary page visit, and the visible attack is a command the user types. Tools that watch downloads or file contents may see little. Microsoft suggests checking browser activity, Run box history in the RunMRU registry key, and scheduled tasks. Does your endpoint tooling log Run box history, wscript.exe launches from Temp, and PowerShell child processes? Who owns that gap?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: iTnews.