ClickFix Browser-Cache Smuggling and Credential-Theft Hunt

Threat Overview

Microsoft Threat Intelligence observed a ClickFix campaign in which compromised websites prefetch a malicious script into the victim browser cache while presenting it as a PNG. The lure then instructs the user to paste a short command into Windows Run. Rather than downloading the first stage directly, the command searches browser-profile cache files whose names begin with f_, selects an entry by expected byte length, copies it to %LOCALAPPDATA%\Temp\t.vbs, and executes it with wscript.exe. This design conceals the staged script inside normal browser-cache activity and keeps the pasted command below the approximately 260-character Windows Run limit.

The observed VBScript launches cmd.exe, gathers host information through WMI, and retrieves v.ps1 from cocojambo[.]us[.]com/alfa. Subsequent PowerShell stages download cab.dat, execute content in a hidden window, load .NET assemblies in memory, and inject into a newly created timeout.exe process to target browser and device credentials. The injected process launches PowerShell to retrieve another in-memory stage from capsysnet[.]vg and communicates with ciliabula[.]cc. These domains and filenames are campaign indicators reported by Microsoft through The Hacker News; they are not universal ClickFix indicators.

References

Impacted Systems

  • Platform: Microsoft Windows endpoints used for interactive web browsing.
  • Components: Windows Run, cmd.exe, Windows Script Host (wscript.exe/cscript.exe), PowerShell, WMI, browser profile/cache directories, and timeout.exe.
  • Browsers: Firefox profile paths were explicitly observed. The technique is conceptually applicable to other locally cached browser content, but other browser paths were not confirmed in the cited campaign.
  • Deployment: User workstations or shared Windows systems; no vulnerable product version is required.
  • Prerequisites: A user visits a compromised or attacker-controlled site and follows the instruction to paste/execute the supplied command.
  • Exposure: Web access to the delivery site and outbound access to campaign infrastructure. The initial cached stage may already be present before the Run command executes.
  • Affected versions/builds: Microsoft did not publish a Windows or browser version boundary; this is social engineering and abuse of trusted utilities rather than a product CVE.

Why this matters

The campaign is active, credential-focused, and designed to reduce obvious download telemetry. Browser-cache staging can evade controls that focus on newly downloaded executables, while the remaining chain uses trusted Windows components and in-memory execution. The technique has broad MSSP applicability because it does not depend on a rare server product and can reach any user permitted to browse and run scripts.

Exploitation Status

Confirmed observed campaign activity. Microsoft described the complete browser-cache smuggling chain and the subsequent credential-theft behavior. Public reporting does not provide victim counts, payload hashes, or attribution. The three domains, /alfa path, and filenames are confirmed for the reported chain but may rotate quickly. No claim is made that all ClickFix activity uses these artifacts.

What this hunt looks for

Browser-cache content copied to t.vbs, script-host and shell ancestry, browser-profile enumeration, the published domains and filenames, hidden PowerShell staging, suspicious timeout.exe behavior, WMI discovery, and the Windows process-event fallback.

Required logs

Microsoft Defender for Endpoint DeviceProcessEvents, DeviceFileEvents, and DeviceNetworkEvents; Windows Security Event 4688 with command-line auditing as a fallback; and DNS, proxy, firewall, or browser URL telemetry for delivery and campaign-infrastructure context.

Hunt 1 — High-signal observed cache-to-VBScript execution chain

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("wscript.exe", "cscript.exe")
| where ProcessCommandLine has "t.vbs" or ProcessCommandLine has @"\AppData\Local\Temp\"
| where InitiatingProcessFileName in~ ("cmd.exe", "explorer.exe", "powershell.exe", "pwsh.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessSHA256
| order by Timestamp desc

Hunt 2 — Browser-cache content copied to the observed t.vbs staging file

let lookback = 30d;
DeviceFileEvents
| where Timestamp >= ago(lookback)
| where FileName =~ "t.vbs" or (FileName endswith ".vbs" and FolderPath has @"\AppData\Local\Temp")
| where InitiatingProcessFileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe")
| project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256, FileSize, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessParentFileName
| order by Timestamp desc

Hunt 3 — Shell enumeration of browser cache/profile files

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe")
| where ProcessCommandLine has_any (@"\Mozilla\Firefox\Profiles", @"\Google\Chrome\User Data", @"\Microsoft\Edge\User Data", "cache2", "Code Cache")
| where ProcessCommandLine has_any ("f_*", "for /r", "Get-ChildItem", "copy", "FileSize", "Length")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc

Hunt 4 — Published campaign domains, path, and staged filenames

let lookback = 30d;
let Domains = dynamic(["cocojambo.us.com", "capsysnet.vg", "ciliabula.cc"]);
DeviceNetworkEvents
| where Timestamp >= ago(lookback)
| where RemoteUrl in~ (Domains) or RemoteUrl has_any ("cocojambo.us.com", "capsysnet.vg", "ciliabula.cc")
    or InitiatingProcessCommandLine has_any ("/alfa", "v.ps1", "cab.dat")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort, Protocol, ActionType
| order by Timestamp desc

Hunt 5 — PowerShell staging and hidden execution indicators

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("powershell.exe", "pwsh.exe")
| where ProcessCommandLine has_any ("cocojambo.us.com", "capsysnet.vg", "ciliabula.cc", "v.ps1", "cab.dat", "Invoke-WebRequest", "DownloadString", "DownloadData", "-WindowStyle Hidden", "-EncodedCommand")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessSHA256
| order by Timestamp desc

Hunt 6 — Suspicious timeout.exe process ancestry or PowerShell child

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where (FileName =~ "timeout.exe" and InitiatingProcessFileName in~ ("powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe", "cmd.exe"))
    or (FileName in~ ("powershell.exe", "pwsh.exe") and InitiatingProcessFileName =~ "timeout.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessSHA256
| order by Timestamp desc

Hunt 7 — Script-host or PowerShell WMI system discovery

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("wmic.exe", "powershell.exe", "pwsh.exe")
| where ProcessCommandLine has_any ("Win32_ComputerSystem", "Win32_OperatingSystem", "Get-CimInstance", "Get-WmiObject", "wmic computersystem", "wmic os")
| where InitiatingProcessFileName in~ ("wscript.exe", "cscript.exe", "cmd.exe", "powershell.exe", "pwsh.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc

Hunt 8 — Browser activity followed by suspicious Run/script execution

let lookback = 14d;
let BrowserNetwork = DeviceNetworkEvents
| where Timestamp >= ago(lookback)
| where InitiatingProcessFileName in~ ("chrome.exe", "msedge.exe", "firefox.exe", "brave.exe")
| project DeviceId, BrowserTime=Timestamp, Browser=InitiatingProcessFileName, RemoteUrl, RemoteIP;
let ScriptStarts = DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("cmd.exe", "wscript.exe", "cscript.exe", "powershell.exe", "pwsh.exe")
| where ProcessCommandLine has_any ("t.vbs", @"\Mozilla\Firefox\Profiles", "cache2", "cab.dat", "v.ps1")
| project DeviceId, ScriptTime=Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine;
BrowserNetwork
| join kind=inner ScriptStarts on DeviceId
| where ScriptTime between (BrowserTime .. BrowserTime + 20m)
| project ScriptTime, DeviceName, AccountName, BrowserTime, Browser, RemoteUrl, RemoteIP, FileName, ProcessCommandLine
| order by ScriptTime desc

Hunt 9 — Windows Security Event process-creation fallback

let lookback = 30d;
SecurityEvent
| where TimeGenerated >= ago(lookback) and EventID == 4688
| where NewProcessName matches regex @"(?i)\\(wscript|cscript|powershell|pwsh|cmd|timeout)\.exe$"
| where CommandLine has_any ("t.vbs", @"\Mozilla\Firefox\Profiles", "cache2", "cocojambo.us.com", "capsysnet.vg", "ciliabula.cc", "v.ps1", "cab.dat")
| project TimeGenerated, Computer, SubjectUserName, ParentProcessName, NewProcessName, CommandLine, NewProcessId
| order by TimeGenerated desc

Detection Notes

  • Hunts 1, 2, 4, 5, and 6 are highest signal because they align directly with the observed chain. t.vbs, v.ps1, and cab.dat are generic names in isolation; validate ancestry, destination, signer, and neighboring activity.
  • The initial website visit and browser cache write can look benign. Defender for Endpoint may record creation or modification of cache entries without proving that their content is malicious, and encrypted browsing can hide the source URL from network devices.
  • Microsoft reported process injection into timeout.exe; ordinary timeout.exe execution is common in scripts. Treat PowerShell as its child, suspicious ancestry, or network activity attributed to it as materially stronger evidence than the image name alone.
  • Domain IOCs may expire or rotate. Behavioral correlation from browser activity to cache enumeration, VBScript, PowerShell, and credential-access behavior should remain useful after infrastructure changes.
  • Hunt 8 can be expensive and noisy. Restrict it to users/devices with a suspicious script event and narrow browser telemetry to the preceding 20 minutes.
  • Missing endpoint file/process/network telemetry, PowerShell logging, DNS/proxy data, or Security Event 4688 collection prevents the corresponding layers from being visible in Sentinel.