My Browser Cache Got Infected

My Browser Cache Got Infected

Source: YouTube · John Hammond · published Sep 17, 2026 · 20:35

Malware Analysis
No ratings yet Log in to rate
Transcript Available
Description

This video analyzes a novel ClickFix campaign where a fake Cloudflare CAPTCHA tricks users into running a command that extracts a malware payload pre-smuggled into their browser cache 0:00.

Key Takeaways:
• The lure mimics a Cloudflare Turnstile check, telling victims to press Windows+R, Ctrl+V, and Enter—executing malicious clipboard content 0:25.
• The one-liner scans Firefox, Chrome, or Brave cache directories for a file exactly 17,635 bytes, copying it to a temp batch script and executing it—payloads are browser-specific 1:00.
• The compromised site posts the victim's user agent to cloudrecycled.com to fingerprint the browser and serve the matching cached payload 2:55.
• The batch payload fakes "verification server" output, then uses curl to pull stage-two PowerShell from a typosquat Cloudflare challenge domain 7:25.
• Stage two displays a fake Cloudflare challenge form in PowerShell as a distraction, then downloads obfuscated C#/.NET stages with shellcode from disguised IP addresses 11:31.
• Sandbox detonation confirms infostealer malware exfiltrating cookies, history, and system metadata to multifilehost.com 19:00.

The cache-smuggling trick—malware hidden in ordinary browser cache and ripped out by the pasted command—shows ClickFix lures keep evolving in cleverness.

Sources:

  • 0:25 Fake Cloudflare CAPTCHA ClickFix lure
  • 1:00 Batch one-liner extracting the 17,635-byte payload from cache
  • 2:55 Browser fingerprinting via cloudrecycled.com
  • 7:25 curl download of next-stage PowerShell
  • 11:31 Fake PowerShell Cloudflare form and obfuscated C# stages
  • 19:00 Infostealer exfiltration to multifilehost.com

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Want a new novel clickfix structure and lure that I haven't seen before? Yes, please. Shout out and thank you to Jerry Blanks for the tip on this one, sharing it and sending it over to me. I'm online at this website, but it's got this annoying manage consent banner. So, I click accept and there is a verify your human Cloudflare turnstile. Except, it's not a real Cloudflare turnstile or I'm not a robot verification. It is a clickfix lure. Ah, let us know you're human. Please complete the steps below. Press the Windows key and R, press Ctrl V, and press Enter. This is a lie. It's a scam. It's social engineering. We would not want to press the Windows key and R on the keyboard and press Ctrl V on the keyboard and then press Enter because we would then be executing that malware. Now, folks are…