Threat actors have been evolving their tactics to stay one step ahead of security measures. A recent wave of attacks has seen malicious payloads being hidden in plain sight, making it increasingly difficult for victims and security professionals alike to detect early warning signs.
ClickFix, a social engineering technique that exploits human trust in software and problem-solving tendencies, has become a prominent attack vector over the past few years. The typical ClickFix scenario involves presenting victims with a fake technical issue or verification prompt, which then instructs them to paste and execute code into Windows Run, PowerShell, or MacOS Terminal. This often involves copying pre-existing code from the clipboard, making it seem like a legitimate action.
However, threat actors have now adapted this technique to better evade detection. According to recent research from Flare and Microsoft Threat Intelligence, attackers are using DNS TXT records and browser cache pre-fetching to conceal malicious payloads until after the victim has taken the initial trusted action. This added layer of complexity makes it even tougher for security measures to identify early attack stages.
One example of this evolution comes from a campaign involving CrocoRat, a remote access Trojan (RAT) and cryptocurrency stealer. Researchers at Flare discovered that instead of directly retrieving the next-stage payload, the pasted PowerShell command queries a DNS TXT record through an attacker-controlled DNS server. This record contains the next PowerShell instruction, directing the system to download additional payloads while keeping them hidden from the clipboard.
What’s more, Flare found evidence that the attackers were experimenting with different payload strategies depending on the victim environment. The script is designed to select persistent remote access for corporate systems and deploy both RATs and credential and cryptocurrency stealers on personal devices. This suggests that the operator may prioritize a quieter foothold on corporate targets, limiting theft activity that could trigger detection.
A second example of this progression comes from Microsoft Threat Intelligence, which revealed a ClickFix campaign involving compromised websites. In this scenario, the website pre-fetches a script payload into the browser cache disguised as a PNG file before instructing the user to paste malicious code. When the victim executes the command, the cached website content is already loaded and ready to be executed, hiding the payload script from view.
These attacks redesign the initial ClickFix-to-payload transition to get past the first line of defense. While EDR solutions can still potentially catch additional payloads, this evolution in tactics makes it increasingly difficult for security measures to keep pace.
As a result, it’s essential for users and organizations to remain vigilant when dealing with suspected phishing or technical issues. This includes being cautious when prompted to paste code into command-line interfaces, verifying the authenticity of websites and emails, and keeping software up-to-date. By staying informed about these emerging threats and taking proactive measures to secure systems, we can better prevent these types of attacks from succeeding.
Source: Dark Reading — 2026-10-06