Cache smuggling: When a picture isn’t a thousand words
ID: 24ba1231-1cd7-5a11-ac79-1ef5b63ea6d3
STIX ID: report--24ba1231-1cd7-5a11-ac79-1ef5b63ea6d3
Feed Name: Expel Blog
Threat Score
This report details a targeted phishing campaign that impersonates a Fortinet VPN compliance checker and leverages a ClickFix-style prompt to paste a hidden command into Windows Explorer; the command runs conhost.exe with a headless PowerShell which copies browser cache files, uses a regex to extract an embedded ZIP (cache smuggling), expands it, and executes a dropped ComplianceChecker executable—bypassing explicit downloads and many detection controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
