ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
A new ClickFix attack technique uses compromised websites to trick users into executing a payload cached in the browser cache rather than downloading one. The sites pre-fetch a script payload into the cache disguised as a PNG file, bypassing Windows Run dialog length limits. Microsoft Threat Intelligence reported the technique on X.