ClickFix Attacks Now Hide Payloads in Your Browser Cache

What happened
Microsoft Threat Intelligence has flagged a new twist on the ClickFix social-engineering playbook, as reported via feeds.feedburner.com in ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits. In this variation, compromised websites quietly pre-fetch a script into the visitor's browser cache, disguised as a PNG image file. The user is then coaxed into running a command that pulls the payload from local cache instead of fetching it from a remote server.
That detail is the whole story. Classic ClickFix lures — the fake "verify you are human" box, the bogus "your browser needs an update" prompt, the phony Teams or document-viewer error — depend on a command that reaches out to the internet to grab something. Here, the malicious content is already sitting on the endpoint before the user ever clicks, which sidesteps the length limits of the Windows Run dialog and gives network-layer inspection far less to notice. The reporting does not spell out which specific sites, industries, or malware families are involved, so treat scope as unconfirmed and verify with your own telemetry rather than assuming you are in or out of the blast radius.

Why this matters for Pittsburgh small and mid-sized businesses
ClickFix works because it recruits the user as the delivery mechanism. There is no attachment to quarantine and no macro to block — a person reads an instruction, copies a string, presses Win+R, and runs it. For a 25-person CPA firm in Wexford or a 120-person manufacturer in the Mon Valley, that is the whole control failure. Your spam filter never sees it. Your firewall sees a staff member browsing a legitimate-looking site that happens to be compromised.
The industries we serve in this region are exactly the ones that research while they work. Attorneys open unfamiliar sites chasing case references. Accountants hit vendor portals and state tax pages, and right now they are heading into year-end planning and the run-up to filing season, when nobody wants to slow down for a weird popup. Healthcare practice managers look up payer policy documents. Manufacturing and defense-contract staff search for spec sheets and distributor part numbers. Every one of those is a normal workflow that lands people on pages their IT provider has never evaluated.
The consequences land differently by vertical. A ClickFix-delivered infostealer that scrapes browser-saved credentials and session tokens can hand an attacker your Microsoft 365 tenant without ever touching a password reset — which means mailbox access, OneDrive and SharePoint contents, and a trusted inbox for the next round of fraud. Under HIPAA that is a potential breach with notification analysis attached. Under the FTC Safeguards Rule, financial-services and tax-preparation firms have to show they had reasonable safeguards in place before the incident, not after. If you handle CUI as a defense supplier, credential theft on a user workstation is a direct hit against your CMMC Level 2 posture and your DFARS incident-reporting obligations. And because the initial access is user-driven, "we have antivirus" is not a defensible answer in a cyber-insurance questionnaire or a client security review.
What to do about it this week
- Tell your team the one rule that stops this. No legitimate website, Microsoft product, or IT provider will ever ask you to copy text and run it in the Windows Run box, PowerShell, or Terminal. If a page asks, close the tab and report it. Say it in an all-hands email today, repeat it in your next staff meeting, and put it in onboarding.
- Block or restrict the Run dialog for standard users. For most non-technical roles there is no business reason to keep Win+R available. Enforce it via Group Policy or Intune, and pair it with constrained-language mode or execution-policy controls on PowerShell for the same population. Pilot with one department first so you find the line-of-business exceptions before you break them.
- Verify your endpoint protection actually detects post-click behavior. Because the payload loads from local cache, prevention shifts to the endpoint. Confirm your EDR or MDR tooling is in block mode (not audit), covers every workstation including remote and BYOD-adjacent machines, and is monitored by a human outside business hours — not just emailing an unread alerts folder.
- Cut off the credential payoff. Stop browser-based password saving in favor of a managed password manager, enforce phishing-resistant or number-matching MFA, and shorten sign-in session lifetimes for privileged accounts. Then confirm your tenant alerts on token-replay and impossible-travel sign-ins so stolen sessions surface fast.
- Hunt for the behavior you would already have logged. Ask for a review of recent process-creation events where a browser or Explorer spawned PowerShell, mshta, or cmd, and of oversized or oddly named cached files. If that data is not being retained, that gap is itself the finding to fix.
- Re-test your incident playbook for a single infected laptop. Who isolates it, who revokes the user's active sessions and resets credentials, who makes the HIPAA, SOC 2, or DFARS notification call, and how fast. Run it as a 30-minute tabletop; the gaps show up immediately.
- Put it on the roadmap, not just the to-do list. Ask your vCIO to document which of these controls are live, which are planned, and which are accepted risks — so the answer exists before a client questionnaire or auditor asks.
If you are also rolling out AI tooling, fold this into that conversation: browser-based AI assistants and copilots expand where users encounter untrusted web content, which is worth covering in your acceptable-use policy and AI readiness assessment rather than handling after the fact.
How we help
PGH Networks runs managed IT and security operations for Pittsburgh-area firms where one tricked employee can become a reportable breach: hardened endpoint policy and patch management, monitored detection and response, Microsoft 365 identity controls, and the documentation your HIPAA, SOC 2, FTC Safeguards, or CMMC obligations require — plus the user training that makes advisories like this one stick.
Want us to confirm whether your environment would stop this attack pattern today? Call 724.888.7007 or reach us through the contact form and we will walk your current controls with you.
Related reading

FBI Warns FortiGate VPN Attacks Are Still Active
The FBI says FortiBleed attacks on exposed FortiGate SSL VPNs are ongoing and locking out admins. Here is what Pittsburgh SMBs should check this week.

FBI Warns FortiBleed Credential Theft Is Still Active
The FBI says the FortiBleed campaign against Fortinet FortiGate firewalls and SSL VPNs is still active. Here is what Pittsburgh SMBs should do this week.

Critical FortiMail Zero-Day Under Active Attack: Patch Now
Fortinet warns of a critical FortiMail flaw, CVE-2026-104286, exploited in zero-day attacks. What Pittsburgh SMBs and defense contractors should do this week.