- Microsoft Threat Intelligence reports a ClickFix campaign that plants a script in the browser cache as a fake PNG, then finds it by file size.
- No conventional download happens when the victim runs the command, so download events are the wrong place to look. Microsoft advises hunting elsewhere.
- Microsoft's advice covers browser activity, Run dialog history, script child processes and scheduled tasks. Use them as a review checklist.
No download at the moment of infection
Download events are a common place to look for signs of an infection. This campaign gives them little to show. When the victim acts, the malicious file is already on the machine, stored as a harmless-looking image.
Microsoft Threat Intelligence described the campaign, as reported by iTnews on October 6. Compromised websites pre-fetched a script into visitors' browser caches, labelled as a PNG image. The cache is the folder where a browser keeps files so pages load faster.
When the victim later ran the attacker's command, Microsoft said, the payload was "already on the device, loaded, and ready to be executed." The lesson here is that defenders who watch for arrival can miss an attack that was placed earlier.
The report does not say whether any tool can spot that earlier pre-fetch from the compromised sites. It says only that the later step involves no conventional download.
How the trick works
This is a ClickFix attack. It poses as a verification or repair prompt and talks the user into running a command. Here, the lure was dressed as a Cloudflare human check. Visitors were told to launch the Windows Run box, paste what was on their clipboard and hit Enter.
The pasted command does three small jobs. It looks through Firefox profile folders for files whose names start with "f_". It picks the one whose size matches an expected value. Then it saves a copy in the Temp folder with a VBScript extension and launches it through wscript.exe, part of Windows Script Host.
Earlier attacks of this kind looked inside cached files for a hidden marker. Microsoft says this campaign compares file size alone. The expected size varied between variants. Microsoft says the approach helps hide the payload and gets around the Run dialog's character limit, because the pasted command only has to find and launch the script.
What happens after the script runs
The chain then fetches more PowerShell stages and compiles .NET code on the victim's machine. That code is injected into the legitimate timeout.exe process. iTnews reports that the target is browser and device credentials.
Microsoft lists three domains the malware uses to receive instructions: cocojambo[.]us[.]com, capsysnet[.]vg and ciliabula[.]cc. For persistence, a scheduled task launches a Python payload.
Hiding payloads in a cache has been done before. What this report adds is a simpler way to find the hidden file again. It also shows a design habit. Several steps lean on built-in Windows tools such as wscript.exe and PowerShell. The injection target, timeout.exe, is a legitimate process.
What Microsoft did not say
Microsoft did not name who was behind the campaign. It did not say how many sites were compromised. It did not identify the credential stealer at the end of the chain. The scale of this campaign is unknown.
The report also describes one campaign and its variants. It does not show how widespread cache smuggling is.
Questions to put to your security team
Microsoft advises hunting across four areas rather than relying on download events. They make a sound starting list for a review.
The four areas are browser activity, Run dialog history stored in the RunMRU registry key, processes launched by WScript and PowerShell, and scheduled tasks. Ask your team these questions.
Can we see Run dialog history on managed devices? Do we log when wscript.exe launches a script from the Temp folder? Do we alert on new scheduled tasks that start Python? Do staff know that a prompt telling them to paste a command into Run is a reason to stop and report it?
The last question matters most. ClickFix lures talk users into running the command themselves. Staff awareness addresses the one step the attacker needs the person to take.
The file did not need to be downloaded when it mattered. It only needed to be waiting.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: iTnews.





