ClickFix Campaigns Hide Payloads Using DNS and Browser Caches

Summary
Researchers describe two ClickFix campaigns that conceal later-stage payloads through DNS TXT records or scripts cached by compromised websites, and recommend user training and controls for PowerShell and command execution.
Key points
- A CrocoRat campaign used a fake CAPTCHA and clipboard-pasted PowerShell command to query an attacker-controlled DNS TXT record for the next instruction.
- Flare found an unexecuted Python launcher suggesting the malware package was being tested for different payload strategies based on the victim environment.
- Microsoft reported a campaign using compromised websites to preload a script disguised as a PNG in the browser cache before the victim runs a copied command.
- The cached script can conceal the payload and avoid the Windows Run dialog's character limit; later PowerShell activity may still be detectable by endpoint tools.
- Recommended defenses include ClickFix-focused user training, web and network protection, application control, and PowerShell script-block logging.
Article Details
- Event Type
- ClickFix social-engineering campaigns evolved to conceal malicious payloads using DNS TXT records and browser-cached scripts.
- Impact
- The techniques can delay detection by hiding next-stage instructions and payloads until after victims execute the copied command. The Flare campaign involved CrocoRat, described as a remote access Trojan and cryptocurrency stealer; the article says its launcher indicated different payload strategies for corporate and personal systems. A separate campaign involved a cluster of compromised websites. The article does not report a quantified impact.
People
Malware
Vendors
FlareFlare cybersecurity researcher Assaf Morag today presented his findings on a new campaign involving CrocoRat, a remote access Trojan (RAT) and cryptocurrency stealer.MicrosoftThe second example of this progression comes from Microsoft Threat Intelligence, which on X shared its findings connected to a ClickFix campaign involving a "cluster" of compromised websites. In this case, the user