Skip to content
New ClickFix Campaign Uses Cache Smuggling for Malware Delivery

New ClickFix Campaign Uses Cache Smuggling for Malware Delivery

First seen 5 Oct 2026, 18:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 18:09 UTC
  • •The ClickFix campaign uses cache smuggling to hide malware in browser caches.
  • •Victims are tricked into executing commands that launch pre-loaded malicious scripts.
  • •Microsoft advises monitoring specific registry keys and browser activity for detection.

Microsoft has reported a new ClickFix campaign that utilizes cache smuggling to hide malware in browser caches, making it ready for execution without explicit downloads. The attack involves compromised websites that pre-load a script disguised as a PNG image file into users' caches. Victims are tricked into executing the malware by pasting commands into the Windows Run dialog, which then retrieves further malicious payloads. The malware targets browser and device credentials and communicates with multiple command and control domains. Microsoft has not disclosed the identity of the attackers or the number of compromised sites. Security experts recommend monitoring browser activity and registry keys to detect this threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
Microsoft reports new ClickFix campaign
Microsoft outlines a campaign using cache smuggling to deliver malware, affecting users through compromised websites.
Itnews.Au
2026-10-05
Expel discusses cache smuggling technique
Expel highlights a phishing lure resembling a VPN compliance tool that uses cache smuggling to install malware.
expel.com

More articles in this cluster (2)

Following this threat?

Track ClickFix and Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How does the malware get executed?
The malware is executed when victims paste commands into the Windows Run dialog, which retrieves pre-loaded scripts from the browser cache.
What should organizations do to protect themselves?
Organizations should monitor browser activity, Run dialog history, and scheduled tasks to detect potential infections.
Are there any known attackers behind this campaign?
Microsoft has not disclosed the identity of the attackers involved in this ClickFix campaign.