Threat reportMalwareTL-2026-2858
ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)
ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache (TL-2026-2858), also tracked as ClickFix browser-cache staging campaign, is a high-severity malware campaign, first published 2026-10-03 and last reviewed 2026-10-04. It has no confirmed attribution, affects Microsoft Windows, maps to 18 MITRE ATT&CK techniques (T1027.004, T1036, T1036.008), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-2858
- Threat ID
- TL-2026-2858
- Also known as
- ClickFix browser-cache staging campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, finance, health, education
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 20
- Updates
- 2026-10-04 · revalidated 1× · latest source
Malware and tooling in ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache
Malware and tooling: Trojan, Trojan:Win32/ClickFix, Trojan:Win32/TermFix
How ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache works
Microsoft Threat Intelligence reports a ClickFix campaign in which compromised websites show fake CAPTCHA-style verification prompts that trick Windows users into pasting a clipboard command into the Run dialog. The command locates a script pre-fetched into the browser cache as a fake PNG, copies it to %LOCALAPPDATA%\Temp .vbs and runs it via wscript.exe, leading to a PowerShell payload (v.ps1), .NET compilation via csc.exe, and persistence through a scheduled task launching a Python payload with pythonw.exe.
Per GBHackers' 2026-10-03 reporting on a Microsoft Threat Intelligence / Microsoft Security Intelligence announcement, a ClickFix campaign delivers its first stage through compromised websites that display a fake CAPTCHA-style verification prompt. The page places a command on the victim's clipboard and instructs the user to open the Windows Run dialog, paste it and press Enter (the command is recorded in the RunMRU registry key).
The novel element is browser-cache staging: the malicious script is pre-fetched by the lure page into the browser cache disguised as a PNG image (cache files beginning with f_). The pasted command runs cmd.exe, which recursively searches the Firefox profile directories under %LOCALAPPDATA%\Mozilla\Firefox\Profiles for the cached file, copies it to %LOCALAPPDATA%\Temp\t.vbs and executes it with wscript.exe. This avoids any network download in the pasted command itself.
The VBScript gathers system information through WMI and downloads the PowerShell script v.ps1 (the article cites cocojambo[.]us[.]com/alfa for PowerShell script retrieval). PowerShell runs with execution policy bypassed, and the per-user PowerShell configuration is modified. A further payload (cab.dat) is downloaded and executed; capsysnet[.]vg is cited for retrieval of a memory-resident stage and ciliabula[.]cc for C2 connections. The chain uses .NET compilation through csc.exe and cvtres.exe, code injection into timeout.exe, extraction of Python components with tar.exe, and a scheduled task that launches the Python payload via pythonw.exe for persistence.
Microsoft detections named in the source are Trojan:Win32/ClickFix, Trojan:Win32/TermFix and a 'Possible ClickFix activity' alert. Recommended defenses: Defender SmartScreen and Defender for Office 365 blocking of malicious sites and lures, cloud-delivered protection, web/network protection, application control, PowerShell script-block logging, monitoring of the RunMRU key, WScript/PowerShell child processes and newly created scheduled tasks. The source does not identify the final payload, a threat actor or a victim count, and the primary Microsoft post was not located; facts here are limited to the GBHackers article, with related Microsoft ClickFix reporting (TerminalFix, Aug 2026) used only as context.
MITRE ATT&CK techniques used in TL-2026-2858
Defense Evasion
T1027.004 Obfuscated Files or Information: Compile After Delivery; T1036 Masquerading; T1036.008 Masquerading: Masquerade File Type; T1055 Process Injection; T1564.003 Hide Artifacts: Hidden Window
Execution
T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.005 Command and Scripting Interpreter: Visual Basic; T1059.006 Command and Scripting Interpreter: Python; T1204.004 User Execution: Malicious Copy and Paste
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1546.013 Event Triggered Execution: PowerShell Profile
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery
Initial Access
Credential Access
T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Affected products and versions in ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache
Remediation for ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache
Immediate actions
- Block cocojambo.us.com, capsysnet.vg and ciliabula.cc at DNS, proxy and firewall
- Hunt for %LOCALAPPDATA%\Temp\t.vbs, cab.dat and wscript.exe launched from cmd.exe spawned by the Run dialog
- Review the RunMRU registry key for pasted cmd/PowerShell commands referencing browser profile paths
- Review recently created scheduled tasks launching pythonw.exe and per-user PowerShell profile changes
Workarounds
- Enable Defender SmartScreen, Defender for Office 365, cloud-delivered protection and web/network protection
Longer-term hardening
- Enable PowerShell script-block logging
- Deploy application control to restrict wscript.exe, csc.exe and PowerShell for standard users
- Consider blocking or auditing the Windows Run dialog for non-administrative users
- Train users that legitimate CAPTCHAs never ask them to paste commands into Run
Timeline of ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache
- Microsoft publishes 'Think before you Click(Fix)' analyzing the ClickFix social engineering technique (background context)
- Microsoft reports the CrashFix ClickFix variant deploying a Python RAT (related Python-payload precedent)
- A builder for ClickFix payload delivery that stores malware in the browser cache is advertised on underground forums (USD 300 builder/source/setup, USD 200 custom template rewrites), showing the technique is commercially available beyond this cluster.
- Microsoft publishes the TerminalFix ClickFix-variant campaign analysis (related campaign, distinct IOCs)
- Crimson7 publishes an independent analysis of browser cache smuggling with ClickFix: payloads served with image Content-Type headers, cached under random hex names, then located and run by a pasted command.
- Microsoft Threat Intelligence posts that it identified compromised websites leading to ClickFix attacks that pre-fetch script payloads into the browser cache as PNG files; stages include .NET assemblies injected into timeout.exe that steal browser and device credentials (date approximate, derived from the LinkedIn post ID).
- Threat ingested by Threadlinqs; no CVE, actor attribution or victim count published in the source
- Microsoft Defender detections named: Trojan:Win32/ClickFix, Trojan:Win32/TermFix and 'Possible ClickFix activity' alert
- Microsoft Threat Intelligence announcement of ClickFix browser-cache staging campaign reported by GBHackers
Update history for TL-2026-2858
- 2026-10-04 — ClickFix campaign via compromised websites staging VBScript payloads in browser cache (Microsoft Threat Intelligence): What changed No severity, exploitability or status change (already HIGH / ACTIVE). The newer report adds impact detail: injected .NET assemblies in timeout.exe steal browser and device credentials, which makes this an infostealer chain. New
Sources cited for ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache
- Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands
- TerminalFix campaign deploys reverse tunnel through multistage intrusion
- Think before you Click(Fix): Analyzing the ClickFix social engineering technique
- ClickFix variant CrashFix deploying Python RAT trojan
- Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging
- ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services
- BleepingComputer: Microsoft warns of TerminalFix attacks deploying reverse tunnels
Detection coverage for TL-2026-2858
As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2858 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.