logo

Cache smuggling: When a picture isn’t a thousand words

ID: 24ba1231-1cd7-5a11-ac79-1ef5b63ea6d3

STIX ID: report--24ba1231-1cd7-5a11-ac79-1ef5b63ea6d3

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2025-10-08

Date Updated: 2026-04-27

Author: Marcus Hutchins

...
...

This report details a targeted phishing campaign that impersonates a Fortinet VPN compliance checker and leverages a ClickFix-style prompt to paste a hidden command into Windows Explorer; the command runs conhost.exe with a headless PowerShell which copies browser cache files, uses a regex to extract an embedded ZIP (cache smuggling), expands it, and executes a dropped ComplianceChecker executable—bypassing explicit downloads and many detection controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.