logo

New FileFix attack uses cache smuggling to evade security software

ID: fe13e6dd-72d1-513a-a068-6f95aa34beb1

STIX ID: report--fe13e6dd-72d1-513a-a068-6f95aa34beb1

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-10-08

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

The report describes a FileFix variant that tricks victims into pasting a padded clipboard path into the Windows File Explorer address bar; the padding hides a headless PowerShell command that copies a cached fake-image from Chrome’s cache, extracts an embedded ZIP and executes a malicious executable. This cache-smuggling technique avoids explicit web downloads and can evade many security products; researchers also observed a ClickFix generator kit used to create these lures and noted adoption by ransomware and infostealer operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.