ClickFix Attack Exploits Browser Cache to Evasion Windows Run Limits
· via The Hacker News
Original source
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
The Hacker News →A new ClickFix attack technique uses compromised websites to trick users into executing payloads stored in their browser cache. By disguising scripts as PNG files, attackers bypass character limits in the Windows Run dialog and execute cached content. The attack chain involves a Visual Basic Script that harvests host information, fetches PowerShell scripts, and ultimately deploys .NET assemblies to steal credentials. This method has become popular due to its ability to turn victims into unwitting malware delivery channels.
Read the full article
Continue reading at The Hacker News →This is an AI-generated summary. Read the original for the full story.