New ClickFix Attack Vector Bypasses Windows Run Limits via Browser Cache Smuggling
A novel ClickFix attack method has emerged, utilizing compromised websites to trick users into executing malicious payloads that have been smuggled into their web browser's cache. Unlike typical attacks that download and execute remote payloads, this variant pre-fetches a script payload, often disguised as a PNG file, directly into the browser cache.
The significance of this technique for practitioners lies in its ability to circumvent a long-standing limitation of the Windows Run dialog, which truncates input exceeding approximately 260 characters. By caching the payload, attackers can execute larger, more complex scripts, such as Visual Basic Scripts (VBScript) that then invoke `cmd.exe` to enumerate files. This method effectively hides the true nature and size of the malicious code, making it harder for web application firewalls (WAFs) and other security measures to detect. Mandiant, a Google-owned security firm, has observed the ShinyHunters group exploiting a bypass for CVE-2026-35273 using URL-encoding tricks to get around WAF rules designed to block vulnerable Oracle PeopleSoft endpoints.
This development fits into a broader trend of attackers increasingly focusing on social engineering and exploiting legitimate system functionalities to achieve their objectives. The attack doesn't rely on breaking into systems directly but rather on manipulating users into executing commands, a tactic that is becoming more prevalent as technical defenses improve. Nation-state actors, such as Sandworm, have also been observed using ClickFix attacks, targeting individuals with PowerShell commands that download VBScript payloads, often delivered via compromised websites. This underscores the need for a multi-layered defense strategy that includes robust user education alongside technical controls.
In practice, organizations should prioritize strengthening their web application firewalls to detect and block such cache-smuggling attempts. Furthermore, user training must emphasize extreme caution when prompted to paste and execute commands, even on seemingly legitimate websites. Microsoft recommends cloud-delivered web and network protection, application control, and PowerShell script-block logging to counter this threat. Developers should also review their web applications for vulnerabilities that could allow for such pre-fetching and caching of malicious content. This incident serves as a stark reminder that the human element remains a critical vulnerability, and attackers will continue to innovate ways to exploit it.
Read original source