Executive Summary
ClickFix has been covered as a lure family — the fake CAPTCHA, the "verify you are human," the instruction to press Win+R and paste. Reading the last three months of research that way makes the activity look like a scattered set of unrelated campaigns. Reading it as an engineering problem makes it coherent.
The problem is that the Windows Run dialog truncates input at approximately 260 characters. Every meaningful ClickFix development this quarter is a way around that ceiling. Microsoft's cache smuggling disclosure in early October pre-stages the payload on disk so the pasted command only has to find it. Cisco Talos's browser variant moves execution out of the OS entirely and reads its payload from a Google Sheet. The blockchain-hosted campaigns BleepingComputer covered across 5,400 compromised sites put the payload somewhere that cannot be taken down. These are three answers to one question.
That reframing has a direct defensive consequence. If you are inspecting the pasted command for malicious content, you are inspecting a loader that is getting shorter and more innocuous by the month. The durable instrumentation is on the paste-to-execute behaviour itself.
AttackAttack Overview
The ClickFix premise has not changed: convince a user to run a command themselves, and you bypass every control that assumes code arrives as a file. No download, no attachment, no macro, no signed-binary question. The user is the delivery mechanism, and the user has already been authenticated by everything that matters.
The constraint has also not changed. A command pasted into Win+R has to fit in roughly 260 characters before Windows truncates it. That is enough for a short PowerShell one-liner with a URL, which is exactly what early ClickFix campaigns used — and exactly what detection engineering learned to catch, because a Run-dialog command containing an encoded PowerShell invocation and an outbound URL is a conspicuous artifact.
So the tradecraft moved. The pasted string is becoming a pointer rather than a payload, and the payload is relocating somewhere that looks legitimate: the browser's own cache, a Google-hosted document, a blockchain. Each relocation makes the pasted command shorter and less distinguishable, and each one shifts the detectable moment later in the chain.
AttackOperator Workflow
Microsoft's cache smuggling variant, documented in early October, is the cleanest illustration. The chain runs:
The lure page pre-fetches the malicious script into the browser cache disguised as a PNG file. This happens during ordinary page rendering — the browser is doing exactly what it is designed to do, fetching an image referenced by a page. Nothing executes.
The user is then instructed to paste a short command. A VBScript entry point invokes `cmd.exe` to recursively enumerate files beginning with `f_` inside the Firefox profile cache at `%LOCALAPPDATA%\Mozilla\Firefox\Profiles`. Crucially, the script identifies the right cache entry by comparing file byte lengths against an expected value rather than searching for a content marker — a choice that defeats content-based scanning of the cache directory, because there is no string to find.
The matching cache entry is copied to `%LOCALAPPDATA%\Temp\t.vbs` and executed via `wscript.exe`. WMI harvests host information. A PowerShell script `v.ps1` is pulled from `cocojambo[.]us[.]com/alfa`, which downloads a further stage `cab.dat` and runs it in a hidden window. .NET assemblies load into memory and inject into the legitimate `timeout.exe` process. The injected process targets browser and device credentials, then retrieves an in-memory stage from `capsysnet[.]vg` and connects to `ciliabula[.]cc`.
The pasted command in that chain does almost nothing on its own. It is a file finder. The malicious content arrived earlier, through a channel no one inspects, as an image.
AttackInfrastructure & Tradecraft
Talos's browser-native variant takes the opposite approach: rather than pre-staging on disk, it never leaves the browser.
Victims are lured with documents impersonating vulnerability reports describing fabricated API flaws at cryptocurrency exchanges, promising higher transaction payouts. Delivery runs through paste.sh links shared via Telegram, with secondary distribution on DarkForums and Pastebin. The victim either pastes a `javascript:` string directly into the Chrome address bar or installs a Tampermonkey userscript — which is the more interesting path, because it relocates persistence from the operating system to a browser extension that survives reboots and loads on every site visit without touching a single OS persistence mechanism defenders monitor.
Command and control runs through the Google Visualization API, a feature introduced in 2008 that provides free, unauthenticated read-only access to any Google Sheet published to the web. A request of the form `https://docs.google[.]com/spreadsheets/d/<id>/gviz/tq?tqx=out:json&tq=SELECT%20B` returns the contents of a column as JSON, ready for the calling script to parse. The operators hid the payload text in the spreadsheet by formatting it white-on-white.
As C2, this is close to ideal. The domain is `docs.google.com`. The certificate is valid. The traffic is indistinguishable from an employee opening a spreadsheet. There is no attacker-controlled infrastructure to block, no domain to sinkhole, and updating the payload means editing a cell.
Talos collected 21 unique second-stage samples. Obfuscation converted the functional script into arrays of hexadecimal pairs that had been XOR encoded, layered with Base64 and Unicode escaping, with a different XOR key and fresh random variable names on each revision — output consistent with `Obfuscator[.]io` and similar tooling. The first-stage script, when executing directly rather than via Tampermonkey, searches the page DOM for script elements associated with browser extensions and, if it finds more than one, picks a random one to inject into.
The payload's objective is cryptocurrency theft through four coordinated techniques: a `MutationObserver` that watches the page and rewrites displayed deposit addresses and transaction amounts; an override of the browser's `fetch` API that inspects and modifies JSON responses containing deposit addresses; clipboard hijacking that substitutes an attacker wallet when the user copies an address; and periodic DOM rescanning so replacements survive page updates. Targeted elements include `data-testid="depositAddress"` and `data-testid="recipientAddressContainer"` on SwapZone.io and SimpleSwap.io. A rotating list of Bitcoin Bech32 addresses was embedded in each script. Of 49 addresses identified, 24 received victim funds totalling 0.159 BTC — roughly $10,000 at early-August 2026 valuations.
Alongside both of these, the broader campaign population moved payloads onto infrastructure that cannot be seized. BleepingComputer documented over 5,400 compromised WordPress and PrestaShop sites serving ClickFix payloads from smart contracts on the BNB Smart Chain Testnet — the technique known as EtherHiding — with more than 300 infected sites active daily and a peak of 536 daily contacts to the blockchain endpoint during August. The Hacker News covered CTM360 research spanning 17,000 URLs showing how extensively ClickFix has converted trusted, legitimate websites into delivery surfaces. Supply-chain injection reached the same end by a different route when the Brevo compromise injected ClickFix scripts into customer sites in mid-September.
DetectionDetection Opportunities
The relocation of the payload is precisely what makes payload-centric detection decay. What survives is the behavioural fingerprint of a human being talked into executing something.
The Run dialog writes every entry to `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU`. That registry key is the most direct evidence that a human typed or pasted a command, and it is written before execution.
DeviceRegistryEvents
| where Timestamp > ago(7d)
| where RegistryKey has @"\Explorer\RunMRU"
| where ActionType in ("RegistryValueSet", "RegistryKeyCreated")
| where RegistryValueData has_any ("powershell", "cmd.exe", "wscript", "mshta",
"curl", "msiexec", "rundll32", "conhost",
"FromBase64String", "IEX", "Invoke-Expression")
| project Timestamp, DeviceName, InitiatingProcessAccountName,
RegistryValueName, RegistryValueDataThe process-lineage signal is stronger because it does not depend on command content at all. A scripting host spawned by a browser or by Explorer is the shape of ClickFix regardless of what the payload turned out to be.
DeviceProcessEvents
| where Timestamp > ago(7d)
| where InitiatingProcessFileName in~ ("explorer.exe", "chrome.exe", "msedge.exe",
"firefox.exe", "brave.exe")
| where FileName in~ ("powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe",
"mshta.exe", "cmd.exe")
| where not(ProcessCommandLine has_any ("--type=", "-ServerName:"))
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName,
FileName, ProcessCommandLine, InitiatingProcessCommandLineFor the cache smuggling variant specifically, the distinctive step is a process reading from the browser cache directory and writing a script file into `Temp`. That sequence has essentially no legitimate counterpart.
DeviceFileEvents
| where Timestamp > ago(7d)
| where FolderPath has_any (@"\Mozilla\Firefox\Profiles", @"\Google\Chrome\User Data")
| where InitiatingProcessFileName in~ ("cmd.exe", "wscript.exe", "cscript.exe",
"powershell.exe", "pwsh.exe")
| join kind=inner (
DeviceFileEvents
| where Timestamp > ago(7d)
| where FolderPath has @"\AppData\Local\Temp"
| where FileName endswith ".vbs" or FileName endswith ".js"
| project WriteTime = Timestamp, DeviceName, DroppedFile = FileName
) on DeviceName
| where WriteTime between (Timestamp .. Timestamp + 5m)
| project Timestamp, WriteTime, DeviceName, InitiatingProcessFileName,
FolderPath, DroppedFileFor the browser-native variant, Talos's guidance is to monitor for HTTP requests to `docs.google[.]com` from unknown applications, or in the context of browser sessions that include no other Google Docs activity. A Visualization API call with no accompanying Docs session is the anomaly; the domain itself never will be.
ValidationLab Recreation
Reproduce this only in an isolated, authorized lab — a disposable VM with no production credentials, no corporate network reachability, and a snapshot to roll back to. Nothing below should be executed against a live target or a machine you do not own, and the point of the exercise is detection validation, not payload development.
Stand up a Windows VM with your EDR agent reporting into a test tenant. Confirm telemetry is flowing before you start, because the most common outcome of a detection lab is discovering a sensor was never reporting.
Validate the RunMRU signal first with a benign command. Press Win+R and run something harmless but matching — `powershell.exe -c "Write-Host lab-test-marker"` — and confirm the registry write appears in `DeviceRegistryEvents` with the command text intact. This proves the field populates and shows you what the data actually looks like. Then run the same thing from a terminal rather than the Run box, and confirm no RunMRU entry appears. That contrast is the signal.
Validate the lineage rule next. From a browser on the VM, trigger a benign scripting-host launch and confirm the parent-child relationship records with the browser as `InitiatingProcessFileName`. Then launch the same scripting host from a legitimate administrative context and confirm it does not match, so you know the rule distinguishes the two.
For the cache-smuggling detection, you do not need malicious content to test the behaviour. Place a benign text file in the Firefox cache directory, then use a script to locate it by byte length, copy it to `%LOCALAPPDATA%\Temp\t.vbs` with inert content, and execute it. The file-event join should fire on the sequence. This exercises the exact detection logic without reproducing the capability — which is the right trade for a defensive lab.
Document which rules fired, which did not, and the latency on each. The rules that did not fire are the output of the exercise.
GapsEvasion & Gaps
The RunMRU keyword list is a liability dressed as a detection. It catches today's loaders because today's loaders still contain recognisable strings, and the entire direction of travel described above is toward pasted commands that contain none. A command that only enumerates files by length and copies one to Temp has no keyword worth matching. Treat keyword matching as a stopgap and weight the lineage rule more heavily — and note that a sufficiently patient operator can break even that by introducing a delay or an intermediate process between the browser and the scripting host.
The Run dialog is not the only paste target. Microsoft's own advisory tells users not to paste commands into Run, Terminal, or PowerShell, and campaigns have already moved toward instructing victims to open a terminal directly. A terminal paste produces no RunMRU artifact at all. Coverage for that case has to come from lineage and from script-block logging, which is the argument for enabling PowerShell script-block logging everywhere rather than treating it as a high-volume luxury.
The browser-native variant largely escapes OS telemetry by construction. Tampermonkey persistence, `fetch` interception and DOM rewriting all occur inside the browser process. EDR sees a browser doing browser things. Realistic coverage requires browser extension management and policy — restricting extension installation by role, as Talos recommends — rather than endpoint detection. Organisations that permit arbitrary extension installation have no detection answer here, only a policy one.
Trusted-domain C2 is the hardest gap and will not close. `docs.google.com` is not blockable. Blockchain-hosted payloads are not seizable. The 17,000-URL CTM360 dataset and the 5,400 compromised sites both point the same direction: the delivery surface is migrating entirely onto infrastructure that is legitimate, high-reputation, and outside anyone's takedown authority. Detection strategies anchored to reputation are already obsolete against this family; the only durable anchor is local behaviour.
Defensive Recommendations
Instrument the paste-to-execute path and treat it as the primary control. RunMRU monitoring plus process lineage from browser and Explorer parents catches the step every variant shares, and it keeps working as payload hosting moves. Enable PowerShell script-block logging broadly so terminal-paste variants are covered when RunMRU is not.
Manage browser extensions by policy. Restrict installation to an approved list and scope developer-level browser functionality by role. This is the only effective answer to the Tampermonkey persistence path, and it is a configuration change rather than a detection project.
Monitor for Google Visualization API requests from browser sessions with no other Google Docs activity, and more generally, build the habit of treating trusted-domain traffic as in-scope for analysis rather than automatically allow-listed. The lesson from this quarter is that the trusted domain is now the C2.
Train on the specific instruction rather than the specific brand. Users should not paste commands from verification prompts into Run, Terminal, or PowerShell — full stop, regardless of whether the prompt says Cloudflare, Google, or anything else. The fake-CAPTCHA framing is interchangeable and already rotating; the "paste this to verify" instruction is the invariant, and it is the one thing worth putting in awareness material.
Finally, for organisations running their own public web properties: the CTM360 and Brevo findings mean your site is a candidate delivery surface, not just a target. Test and sanitise third-party dependencies regularly, and check for obfuscated script that appears out of place in your own JavaScript. A large share of this quarter's ClickFix delivery came from legitimate sites whose owners did not know they were serving it.