Threat reportMalwareTL-2026-2858

ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)

highACTIVE

ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache (TL-2026-2858), also tracked as ClickFix browser-cache staging campaign, is a high-severity malware campaign, first published 2026-10-03 and last reviewed 2026-10-04. It has no confirmed attribution, affects Microsoft Windows, maps to 18 MITRE ATT&CK techniques (T1027.004, T1036, T1036.008), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-2858

Threat ID
TL-2026-2858
Also known as
ClickFix browser-cache staging campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, finance, health, education
Target regions
Global
Detection rules
9
Indicators of compromise
20
Updates
2026-10-04 · revalidated 1× · latest source

Malware and tooling in ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache

Malware and tooling: Trojan, Trojan:Win32/ClickFix, Trojan:Win32/TermFix

How ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache works

Microsoft Threat Intelligence reports a ClickFix campaign in which compromised websites show fake CAPTCHA-style verification prompts that trick Windows users into pasting a clipboard command into the Run dialog. The command locates a script pre-fetched into the browser cache as a fake PNG, copies it to %LOCALAPPDATA%\Temp .vbs and runs it via wscript.exe, leading to a PowerShell payload (v.ps1), .NET compilation via csc.exe, and persistence through a scheduled task launching a Python payload with pythonw.exe.

Per GBHackers' 2026-10-03 reporting on a Microsoft Threat Intelligence / Microsoft Security Intelligence announcement, a ClickFix campaign delivers its first stage through compromised websites that display a fake CAPTCHA-style verification prompt. The page places a command on the victim's clipboard and instructs the user to open the Windows Run dialog, paste it and press Enter (the command is recorded in the RunMRU registry key).

The novel element is browser-cache staging: the malicious script is pre-fetched by the lure page into the browser cache disguised as a PNG image (cache files beginning with f_). The pasted command runs cmd.exe, which recursively searches the Firefox profile directories under %LOCALAPPDATA%\Mozilla\Firefox\Profiles for the cached file, copies it to %LOCALAPPDATA%\Temp\t.vbs and executes it with wscript.exe. This avoids any network download in the pasted command itself.

The VBScript gathers system information through WMI and downloads the PowerShell script v.ps1 (the article cites cocojambo[.]us[.]com/alfa for PowerShell script retrieval). PowerShell runs with execution policy bypassed, and the per-user PowerShell configuration is modified. A further payload (cab.dat) is downloaded and executed; capsysnet[.]vg is cited for retrieval of a memory-resident stage and ciliabula[.]cc for C2 connections. The chain uses .NET compilation through csc.exe and cvtres.exe, code injection into timeout.exe, extraction of Python components with tar.exe, and a scheduled task that launches the Python payload via pythonw.exe for persistence.

Microsoft detections named in the source are Trojan:Win32/ClickFix, Trojan:Win32/TermFix and a 'Possible ClickFix activity' alert. Recommended defenses: Defender SmartScreen and Defender for Office 365 blocking of malicious sites and lures, cloud-delivered protection, web/network protection, application control, PowerShell script-block logging, monitoring of the RunMRU key, WScript/PowerShell child processes and newly created scheduled tasks. The source does not identify the final payload, a threat actor or a victim count, and the primary Microsoft post was not located; facts here are limited to the GBHackers article, with related Microsoft ClickFix reporting (TerminalFix, Aug 2026) used only as context.

MITRE ATT&CK techniques used in TL-2026-2858

Defense Evasion

T1027.004 Obfuscated Files or Information: Compile After Delivery; T1036 Masquerading; T1036.008 Masquerading: Masquerade File Type; T1055 Process Injection; T1564.003 Hide Artifacts: Hidden Window

Execution

T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.005 Command and Scripting Interpreter: Visual Basic; T1059.006 Command and Scripting Interpreter: Python; T1204.004 User Execution: Malicious Copy and Paste

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1546.013 Event Triggered Execution: PowerShell Profile

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer

Discovery

T1082 System Information Discovery

Initial Access

T1189 Drive-by Compromise

Credential Access

T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Affected products and versions in ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints where users can open the Run dialog and execute wscript.exe/PowerShell
  • Mozilla — Firefox
    Vulnerable versions: Firefox profile cache used as staging location

Remediation for ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache

Immediate actions

  • Block cocojambo.us.com, capsysnet.vg and ciliabula.cc at DNS, proxy and firewall
  • Hunt for %LOCALAPPDATA%\Temp\t.vbs, cab.dat and wscript.exe launched from cmd.exe spawned by the Run dialog
  • Review the RunMRU registry key for pasted cmd/PowerShell commands referencing browser profile paths
  • Review recently created scheduled tasks launching pythonw.exe and per-user PowerShell profile changes

Workarounds

  • Enable Defender SmartScreen, Defender for Office 365, cloud-delivered protection and web/network protection

Longer-term hardening

  • Enable PowerShell script-block logging
  • Deploy application control to restrict wscript.exe, csc.exe and PowerShell for standard users
  • Consider blocking or auditing the Windows Run dialog for non-administrative users
  • Train users that legitimate CAPTCHAs never ask them to paste commands into Run

Timeline of ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache

  • Microsoft publishes 'Think before you Click(Fix)' analyzing the ClickFix social engineering technique (background context)
  • Microsoft reports the CrashFix ClickFix variant deploying a Python RAT (related Python-payload precedent)
  • A builder for ClickFix payload delivery that stores malware in the browser cache is advertised on underground forums (USD 300 builder/source/setup, USD 200 custom template rewrites), showing the technique is commercially available beyond this cluster.
  • Microsoft publishes the TerminalFix ClickFix-variant campaign analysis (related campaign, distinct IOCs)
  • Crimson7 publishes an independent analysis of browser cache smuggling with ClickFix: payloads served with image Content-Type headers, cached under random hex names, then located and run by a pasted command.
  • Microsoft Threat Intelligence posts that it identified compromised websites leading to ClickFix attacks that pre-fetch script payloads into the browser cache as PNG files; stages include .NET assemblies injected into timeout.exe that steal browser and device credentials (date approximate, derived from the LinkedIn post ID).
  • Threat ingested by Threadlinqs; no CVE, actor attribution or victim count published in the source
  • Microsoft Defender detections named: Trojan:Win32/ClickFix, Trojan:Win32/TermFix and 'Possible ClickFix activity' alert
  • Microsoft Threat Intelligence announcement of ClickFix browser-cache staging campaign reported by GBHackers

Update history for TL-2026-2858

Sources cited for ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache

Detection coverage for TL-2026-2858

As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2858 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats