Microsoft Threat Intelligence has documented a ClickFix variant that stashes its payload in the victim’s browser cache disguised as a PNG image, then tells the victim to paste a short command that runs the cached content. The technique gets around the roughly 260-character limit of the Windows Run dialog, opened with Win + R.
How the Cached PNG Gets Around the Windows Run Dialog Limit
ClickFix attacks trick a user into pasting a command into the Windows Run dialog. That dialog caps input at about 260 characters, which constrains how much malicious logic an attacker can place in the command. Microsoft observed compromised websites prefetching a script payload into the browser cache, labeled as a PNG, before the victim does anything. The victim is then told to paste a short command that executes content that is already on the machine.
Because the payload arrives earlier through ordinary web caching, nothing is downloaded from a remote server at the moment of pasting. That makes the final step harder to spot with controls that watch for a download at execution time.
The VBScript Stage That Finds the Cached File
The short command launches a VBScript that enumerates files whose names begin with “f_” in browser profile folders. It matches the file it wants by its expected byte length, copies it to %LOCALAPPDATA%Tempt.vbs and runs it with wscript.exe.
From t.vbs to In-Memory .NET Assemblies Injected Into timeout.exe
The copied VBScript collects host information through Windows Management Instrumentation, then fetches a PowerShell script named v.ps1 from cocojambo[.]us[.]com/alfa. That script downloads a file called cab.dat and runs .NET assemblies in memory. The assemblies are injected into timeout.exe, a legitimate Windows utility, and steal browser and device credentials.
A secondary stage is retrieved from capsysnet[.]vg, and the malware makes outbound connections to ciliabula[.]cc. These domains are among the indicators published in Microsoft’s analysis.
Credential Theft Inside timeout.exe
Injecting into timeout.exe places the credential-stealing code inside a process that normally does nothing of interest, which can reduce the visibility of the activity for tools that flag unfamiliar executables. Running the assemblies in memory also avoids writing the final stealer to disk, though the earlier t.vbs file does land in the Temp folder.
The sequence has several stages, each with a distinct footprint. First comes the prefetch of the disguised payload by a compromised site. Second, the victim pastes the short command. Third, the VBScript locates and copies the cached file. Fourth, wscript.exe runs it, and the PowerShell and .NET stages follow. Each stage creates an observable event, and a defender who sees the first can intervene before credentials leave the device.
Cache Smuggling Is Not New: Expel Documented a Similar Chain in October 2025
Microsoft’s finding is not the first use of cache smuggling in this kind of attack. Expel documented a similar chain in October 2025. The new variant combines it with the ClickFix prompt, so the pasted command no longer needs to carry the payload.
ClickFix has relied on the victim doing the final step manually, which bypasses many automated defenses because the user, not a downloader, starts execution. Moving the heavy payload into the cache ahead of time keeps that advantage while shrinking what the pasted command must contain.
Defenders now have a few concrete artifacts to look for: files named with the “f_” prefix in browser profile folders, a t.vbs file in the user’s Temp directory, wscript.exe launched from that path, and timeout.exe behaving unusually. Microsoft published the analysis and the indicators, and the reporting does not say how many victims there are, which sites were compromised or who is running the campaign.
