Cybersecurity researchers have uncovered a new threat actor hawking a sneaky tool called “ClickFix.” This payload-delivery method claims to hide malware in your browser’s cache folder.
Dodge detection tools and slip past endpoint detection and response (EDR) systems. Sold on underground forums, it’s pitched as a way to infect machines without triggering alarms from suspicious downloads or web traffic.
The seller boasts that ClickFix skips the usual red flags. No big file downloads or odd network calls that security software loves to spot. Instead, it tricks users into running a fake “fix” for a browser issue.
Once clicked, the payload plants itself in the browser cache a spot most antivirus scans overlook. From there, it uses hidden File Explorer commands to launch the malware. This keeps everything looking innocent, as if it were routine browser maintenance.
Experts warn that this fits a rising trend. Attackers increasingly target browser storage because it’s temporary and user-controlled. Cache folders store web data, such as images and scripts, but they’re not locked down like program files.
EDR tools often ignore them during scans, assuming they’re harmless leftovers. ClickFix exploits this blind spot, making it ideal for red-team exercises or real-world attacks.
How ClickFix Works Step by Step
ClickFix starts with a phishing lure. Victims get an email or link claiming their browser needs a quick update. They see a pop-up or shortcut labeled “Click to Fix Cache Error.”
When users click it, a script runs in the background. It grabs a small encoded payload from a legitimate-looking site nothing over a few kilobytes to avoid network monitors.
The magic happens next. The script decodes the payload and drops it into the browser’s cache directory, such as Chrome’s User Data/Default/Cache on Windows. It renames the file to mimic a thumbnail or temp file, like “cache_001.dat.”
No writes to system folders or registry changes that scream malware. To execute, ClickFix crafts a disguised command for File Explorer. Something like “explorer.exe /root,CacheFolder:RunPayload.”
This blends into normal Explorer activity, bypassing behavioral rules in tools like CrowdStrike or Microsoft Defender.

According to Dark Web Informer, once running, the malware can do anything: steal data, deploy ransomware, or set up a backdoor. The seller claims it’s EDR-proof because it chains short-lived processes.
Each step lasts seconds, under the radar of memory scans or process trees. Researchers tested a sample and confirmed it evades basic signatures. But advanced behavioral analytics might catch the Explorer abuse if tuned right.
For proof, check forum posts on sites like Exploit. in or BreachForums, where the ad appeared last week [source: Dark Web Monitor, Feb 2026]. A demo video shows it infecting a virtual machine without alerts.
Sale Details and Why It Matters Now
The full package costs $300 in crypto. Buyers get the source code (JavaScript and PowerShell), a builder GUI, a setup guide, and a ready template for lures.
For an extra $200, the seller can customize the phishing page to match the branding of companies like Google or Microsoft. Delivery is instant via encrypted links, with “lifetime updates” promised.
This isn’t just hype. Similar cache-trick-powered attacks like the 2025 Magecart variants hid skimmers in browser storage [Read more: Krebs on Security].
As browsers tighten sandboxing, cache abuse will grow. Orgs should scan cache folders in EDR rules, block unusual Explorer args, and train users on fake fixes.
Defenders, act fast: Update browser policies to clear cache on exit and monitor PowerShell in browsers. Threat hunters hunt for anomalies in “cache_*.dat” files. This low-tech trick proves evasion arms races never end.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.