New ClickFix Variant Exploits Browser Cache to Deliver Malicious Code Undetected

Researchers from Microsoft Threat Intelligence identified a novel variant of ClickFix attacks that leverages browser cache mechanisms to bypass Windows execution restrictions. The attack disguises malicious script payloads as PNG image files that are pre-fetched by compromised websites, avoiding the traditional download-and-execute pattern that security tools typically monitor. This approach represents an evolution in obfuscation techniques used by the ClickFix threat actor.
Researchers at Microsoft's threat intelligence division have uncovered an updated version of the ClickFix malware campaign that uses a more sophisticated delivery mechanism. Rather than following conventional infection patterns, this variant embeds harmful code within image files that are automatically loaded into a system's browser storage. By disguising payloads as legitimate PNG graphics, the attack circumvents detection systems designed to intercept typical executable downloads and installations.
This advancement highlights how threat actors continuously refine their methods to evade security defenses. The technique represents a meaningful shift in how ClickFix operators attempt to compromise Windows systems, demonstrating their focus on exploiting legitimate browser functionality to mask malicious intent.
This variant could pose particular risks to organizations and individuals relying on traditional endpoint security tools that prioritize monitoring direct downloads and program execution. Users of compromised websites may face infection without typical warning signs, potentially affecting business operations and personal data security. However, the discovery and documentation by Microsoft may enable security vendors to develop countermeasures, helping mitigate broader exposure as awareness of the technique spreads through the cybersecurity community.