Threat Overview
Microsoft Threat Intelligence observed a ClickFix campaign in which compromised websites prefetch a malicious script into the victim browser cache while presenting it as a PNG. The lure then instructs the user to paste a short command into Windows Run. Rather than downloading the first stage directly, the command searches browser-profile cache files whose names begin with f_, selects an entry by expected byte length, copies it to %LOCALAPPDATA%\Temp\t.vbs, and executes it with wscript.exe. This design conceals the staged script inside normal browser-cache activity and keeps the pasted command below the approximately 260-character Windows Run limit.
The observed VBScript launches cmd.exe, gathers host information through WMI, and retrieves v.ps1 from cocojambo[.]us[.]com/alfa. Subsequent PowerShell stages download cab.dat, execute content in a hidden window, load .NET assemblies in memory, and inject into a newly created timeout.exe process to target browser and device credentials. The injected process launches PowerShell to retrieve another in-memory stage from capsysnet[.]vg and communicates with ciliabula[.]cc. These domains and filenames are campaign indicators reported by Microsoft through The Hacker News; they are not universal ClickFix indicators.
References
- The Hacker News, “ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits,” published October 6, 2026: https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html
- Microsoft Threat Intelligence, campaign observations quoted and technically summarized by The Hacker News on October 6, 2026: https://x.com/MsftSecIntel
- MITRE ATT&CK, User Execution: Malicious File (T1204.002), Visual Basic (T1059.005), PowerShell (T1059.001), Process Injection (T1055), and Credentials from Web Browsers (T1555.003): https://attack.mitre.org/
Impacted Systems
- Platform: Microsoft Windows endpoints used for interactive web browsing.
- Components: Windows Run,
cmd.exe, Windows Script Host (wscript.exe/cscript.exe), PowerShell, WMI, browser profile/cache directories, andtimeout.exe. - Browsers: Firefox profile paths were explicitly observed. The technique is conceptually applicable to other locally cached browser content, but other browser paths were not confirmed in the cited campaign.
- Deployment: User workstations or shared Windows systems; no vulnerable product version is required.
- Prerequisites: A user visits a compromised or attacker-controlled site and follows the instruction to paste/execute the supplied command.
- Exposure: Web access to the delivery site and outbound access to campaign infrastructure. The initial cached stage may already be present before the Run command executes.
- Affected versions/builds: Microsoft did not publish a Windows or browser version boundary; this is social engineering and abuse of trusted utilities rather than a product CVE.
Why this matters
The campaign is active, credential-focused, and designed to reduce obvious download telemetry. Browser-cache staging can evade controls that focus on newly downloaded executables, while the remaining chain uses trusted Windows components and in-memory execution. The technique has broad MSSP applicability because it does not depend on a rare server product and can reach any user permitted to browse and run scripts.
Exploitation Status
Confirmed observed campaign activity. Microsoft described the complete browser-cache smuggling chain and the subsequent credential-theft behavior. Public reporting does not provide victim counts, payload hashes, or attribution. The three domains, /alfa path, and filenames are confirmed for the reported chain but may rotate quickly. No claim is made that all ClickFix activity uses these artifacts.
What this hunt looks for
Browser-cache content copied to t.vbs, script-host and shell ancestry, browser-profile enumeration, the published domains and filenames, hidden PowerShell staging, suspicious timeout.exe behavior, WMI discovery, and the Windows process-event fallback.
Required logs
Microsoft Defender for Endpoint DeviceProcessEvents, DeviceFileEvents, and DeviceNetworkEvents; Windows Security Event 4688 with command-line auditing as a fallback; and DNS, proxy, firewall, or browser URL telemetry for delivery and campaign-infrastructure context.
Hunt 1 — High-signal observed cache-to-VBScript execution chain
let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("wscript.exe", "cscript.exe")
| where ProcessCommandLine has "t.vbs" or ProcessCommandLine has @"\AppData\Local\Temp\"
| where InitiatingProcessFileName in~ ("cmd.exe", "explorer.exe", "powershell.exe", "pwsh.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessSHA256
| order by Timestamp desc
Hunt 2 — Browser-cache content copied to the observed t.vbs staging file
let lookback = 30d;
DeviceFileEvents
| where Timestamp >= ago(lookback)
| where FileName =~ "t.vbs" or (FileName endswith ".vbs" and FolderPath has @"\AppData\Local\Temp")
| where InitiatingProcessFileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe")
| project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256, FileSize, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessParentFileName
| order by Timestamp desc
Hunt 3 — Shell enumeration of browser cache/profile files
let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe")
| where ProcessCommandLine has_any (@"\Mozilla\Firefox\Profiles", @"\Google\Chrome\User Data", @"\Microsoft\Edge\User Data", "cache2", "Code Cache")
| where ProcessCommandLine has_any ("f_*", "for /r", "Get-ChildItem", "copy", "FileSize", "Length")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc
Hunt 4 — Published campaign domains, path, and staged filenames
let lookback = 30d;
let Domains = dynamic(["cocojambo.us.com", "capsysnet.vg", "ciliabula.cc"]);
DeviceNetworkEvents
| where Timestamp >= ago(lookback)
| where RemoteUrl in~ (Domains) or RemoteUrl has_any ("cocojambo.us.com", "capsysnet.vg", "ciliabula.cc")
or InitiatingProcessCommandLine has_any ("/alfa", "v.ps1", "cab.dat")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort, Protocol, ActionType
| order by Timestamp desc
Hunt 5 — PowerShell staging and hidden execution indicators
let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("powershell.exe", "pwsh.exe")
| where ProcessCommandLine has_any ("cocojambo.us.com", "capsysnet.vg", "ciliabula.cc", "v.ps1", "cab.dat", "Invoke-WebRequest", "DownloadString", "DownloadData", "-WindowStyle Hidden", "-EncodedCommand")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessSHA256
| order by Timestamp desc
Hunt 6 — Suspicious timeout.exe process ancestry or PowerShell child
let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where (FileName =~ "timeout.exe" and InitiatingProcessFileName in~ ("powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe", "cmd.exe"))
or (FileName in~ ("powershell.exe", "pwsh.exe") and InitiatingProcessFileName =~ "timeout.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessSHA256
| order by Timestamp desc
Hunt 7 — Script-host or PowerShell WMI system discovery
let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("wmic.exe", "powershell.exe", "pwsh.exe")
| where ProcessCommandLine has_any ("Win32_ComputerSystem", "Win32_OperatingSystem", "Get-CimInstance", "Get-WmiObject", "wmic computersystem", "wmic os")
| where InitiatingProcessFileName in~ ("wscript.exe", "cscript.exe", "cmd.exe", "powershell.exe", "pwsh.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc
Hunt 8 — Browser activity followed by suspicious Run/script execution
let lookback = 14d;
let BrowserNetwork = DeviceNetworkEvents
| where Timestamp >= ago(lookback)
| where InitiatingProcessFileName in~ ("chrome.exe", "msedge.exe", "firefox.exe", "brave.exe")
| project DeviceId, BrowserTime=Timestamp, Browser=InitiatingProcessFileName, RemoteUrl, RemoteIP;
let ScriptStarts = DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("cmd.exe", "wscript.exe", "cscript.exe", "powershell.exe", "pwsh.exe")
| where ProcessCommandLine has_any ("t.vbs", @"\Mozilla\Firefox\Profiles", "cache2", "cab.dat", "v.ps1")
| project DeviceId, ScriptTime=Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine;
BrowserNetwork
| join kind=inner ScriptStarts on DeviceId
| where ScriptTime between (BrowserTime .. BrowserTime + 20m)
| project ScriptTime, DeviceName, AccountName, BrowserTime, Browser, RemoteUrl, RemoteIP, FileName, ProcessCommandLine
| order by ScriptTime desc
Hunt 9 — Windows Security Event process-creation fallback
let lookback = 30d;
SecurityEvent
| where TimeGenerated >= ago(lookback) and EventID == 4688
| where NewProcessName matches regex @"(?i)\\(wscript|cscript|powershell|pwsh|cmd|timeout)\.exe$"
| where CommandLine has_any ("t.vbs", @"\Mozilla\Firefox\Profiles", "cache2", "cocojambo.us.com", "capsysnet.vg", "ciliabula.cc", "v.ps1", "cab.dat")
| project TimeGenerated, Computer, SubjectUserName, ParentProcessName, NewProcessName, CommandLine, NewProcessId
| order by TimeGenerated desc
Detection Notes
- Hunts 1, 2, 4, 5, and 6 are highest signal because they align directly with the observed chain.
t.vbs,v.ps1, andcab.datare generic names in isolation; validate ancestry, destination, signer, and neighboring activity. - The initial website visit and browser cache write can look benign. Defender for Endpoint may record creation or modification of cache entries without proving that their content is malicious, and encrypted browsing can hide the source URL from network devices.
- Microsoft reported process injection into
timeout.exe; ordinarytimeout.exeexecution is common in scripts. Treat PowerShell as its child, suspicious ancestry, or network activity attributed to it as materially stronger evidence than the image name alone. - Domain IOCs may expire or rotate. Behavioral correlation from browser activity to cache enumeration, VBScript, PowerShell, and credential-access behavior should remain useful after infrastructure changes.
- Hunt 8 can be expensive and noisy. Restrict it to users/devices with a suspicious script event and narrow browser telemetry to the preceding 20 minutes.
- Missing endpoint file/process/network telemetry, PowerShell logging, DNS/proxy data, or Security Event 4688 collection prevents the corresponding layers from being visible in Sentinel.