# ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)

> Microsoft Threat Intelligence reports a ClickFix campaign in which compromised websites show fake CAPTCHA-style verification prompts that trick Windows users into pasting a clipboard command into the Run dialog. The command locates a script pre-fetched into the browser cache as a fake PNG, copies it to %LOCALAPPDATA%\Temp	.vbs and runs it via wscript.exe, leading to a PowerShell payload (v.ps1), .NET compilation via csc.exe, and persistence through a scheduled task launching a Python payload with pythonw.exe.

- **Published:** 2026-10-03T00:00:00Z
- **Last reviewed:** 2026-10-04T15:28:54.484Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2858
- **ID:** TL-2026-2858
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Per GBHackers' 2026-10-03 reporting on a Microsoft Threat Intelligence / Microsoft Security Intelligence announcement, a ClickFix campaign delivers its first stage through compromised websites that display a fake CAPTCHA-style verification prompt. The page places a command on the victim's clipboard and instructs the user to open the Windows Run dialog, paste it and press Enter (the command is recorded in the RunMRU registry key).

The novel element is browser-cache staging: the malicious script is pre-fetched by the lure page into the browser cache disguised as a PNG image (cache files beginning with f_). The pasted command runs cmd.exe, which recursively searches the Firefox profile directories under %LOCALAPPDATA%\Mozilla\Firefox\Profiles for the cached file, copies it to %LOCALAPPDATA%\Temp\t.vbs and executes it with wscript.exe. This avoids any network download in the pasted command itself.

The VBScript gathers system information through WMI and downloads the PowerShell script v.ps1 (the article cites cocojambo[.]us[.]com/alfa for PowerShell script retrieval). PowerShell runs with execution policy bypassed, and the per-user PowerShell configuration is modified. A further payload (cab.dat) is downloaded and executed; capsysnet[.]vg is cited for retrieval of a memory-resident stage and ciliabula[.]cc for C2 connections. The chain uses .NET compilation through csc.exe and cvtres.exe, code injection into timeout.exe, extraction of Python components with tar.exe, and a scheduled task that launches the Python payload via pythonw.exe for persistence.

Microsoft detections named in the source are Trojan:Win32/ClickFix, Trojan:Win32/TermFix and a 'Possible ClickFix activity' alert. Recommended defenses: Defender SmartScreen and Defender for Office 365 blocking of malicious sites and lures, cloud-delivered protection, web/network protection, application control, PowerShell script-block logging, monitoring of the RunMRU key, WScript/PowerShell child processes and newly created scheduled tasks. The source does not identify the final payload, a threat actor or a victim count, and the primary Microsoft post was not located; facts here are limited to the GBHackers article, with related Microsoft ClickFix reporting (TerminalFix, Aug 2026) used only as context.

## MITRE ATT&CK

- T1204.004 User Execution: Malicious Copy and Paste
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.006 Command and Scripting Interpreter: Python
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1546.013 Event Triggered Execution: PowerShell Profile
- T1027.004 Obfuscated Files or Information: Compile After Delivery
- T1036 Masquerading
- T1055 Process Injection
- T1082 System Information Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1189 Drive-by Compromise
- T1036.008 Masquerading: Masquerade File Type
- T1564.003 Hide Artifacts: Hidden Window
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1105 Ingress Tool Transfer

## Sources

- [Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands](https://gbhackers.com/microsoft-warns-clickfix-attacks-use-fake-captcha/)
- [TerminalFix campaign deploys reverse tunnel through multistage intrusion](https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/)
- [Think before you Click(Fix): Analyzing the ClickFix social engineering technique](https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/)
- [ClickFix variant CrashFix deploying Python RAT trojan](https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan)
- [Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging](https://thehackernews.com/2026/02/microsoft-discloses-dns-based-clickfix.html)
- [ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services](https://thehackernews.com/2026/01/clickfix-attacks-expand-using-fake.html)
- [BleepingComputer: Microsoft warns of TerminalFix attacks deploying reverse tunnels](https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2858
