iTnews reported on 6 October 2026 that Microsoft Threat Intelligence found a new ClickFix campaign. ClickFix tricks people into running an attacker's command themselves. Hacked websites quietly left a script in visitors' browser caches, labelled as a PNG image. A fake Cloudflare human check then told users to paste a command into the Windows Run box.
Microsoft said the command hunts through Firefox profile folders for files with an f_ prefix and picks the one with the expected size. It saves that file in Temp as a VBScript and starts it. Expel's Marcus Hutchins described cache smuggling in October 2025, when attackers searched for a hidden marker inside files. Microsoft did not name the attackers, say how many sites were hacked, or say which credential stealer was used.
In our reading, the file arrives during an ordinary page visit, and the visible attack is a command the user types. Tools that watch downloads or file contents may see little. Microsoft suggests checking browser activity, Run box history in the RunMRU registry key, and scheduled tasks. Does your endpoint tooling log Run box history, wscript.exe launches from Temp, and PowerShell child processes? Who owns that gap?