Itnews.Au New ClickFix Campaign Uses Cache Smuggling for Malware Delivery
Article Content
- •The ClickFix campaign uses cache smuggling to hide malware in browser caches.
- •Victims are tricked into executing commands that launch pre-loaded malicious scripts.
- •Microsoft advises monitoring specific registry keys and browser activity for detection.
Microsoft has reported a new ClickFix campaign that utilizes cache smuggling to hide malware in browser caches, making it ready for execution without explicit downloads. The attack involves compromised websites that pre-load a script disguised as a PNG image file into users' caches. Victims are tricked into executing the malware by pasting commands into the Windows Run dialog, which then retrieves further malicious payloads. The malware targets browser and device credentials and communicates with multiple command and control domains. Microsoft has not disclosed the identity of the attackers or the number of compromised sites. Security experts recommend monitoring browser activity and registry keys to detect this threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ClickFix and Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How does the malware get executed?
What should organizations do to protect themselves?
Are there any known attackers behind this campaign?
Continue Reading
New ChainScript RAT Exploits ClickFix Lures with Blockchain C2 A newly discovered Node.js remote access trojan (RAT) named ChainScript is being deployed through ClickFix social engineering tactics, targeting Windows systems. The malware utilizes a unique command-and-control (C2) discovery method by querying a Polygon blockchain smart contract to dynamically rotate its server…
Cybercriminals Exploit ChatGPT Custom GPTs for ClickFix RAT Attacks A new ClickFix campaign has been discovered that exploits ChatGPT Custom GPTs to impersonate legitimate products, luring users into executing malicious code. Cybersecurity firm Huntress reported that at least 40 users have been infected, with two confirmed incidents linked to Custom GPT instances. The attackers…