ClickFix Attacks Evolve to Leverage DNS TXT Records and Browser Pre-fetching for Payload Hiding
ClickFix attacks are evolving to evade detection by using DNS TXT records to hide malicious payloads and browser cache pre-fetching to stage them. This sophisticated technique makes early-stage attack identification more challenging for defenders, as it obscures the initial delivery mechanisms.
Overview
ClickFix attacks have adopted new evasion techniques, specifically leveraging DNS TXT records for payload storage and browser cache pre-fetching for staging. This evolution aims to obscure the initial stages of the attack chain, making it harder for security tools to identify and block malicious activity before execution. The techniques allow threat actors to bypass traditional network filtering and detection mechanisms focused on common payload delivery protocols.
Technical Analysis
Threat actors are enhancing ClickFix attacks by employing two primary methods to hide and stage malicious payloads:
- Payload Hiding via DNS TXT Records: Malicious code, URLs, or command-and-control (C2) instructions are embedded within DNS TXT records. When a victim’s system resolves a specific domain, it retrieves the TXT record, which then contains the hidden payload or a pointer to it. This method allows for data exfiltration or ingress tool transfer over DNS, bypassing network defenses that might not inspect DNS query content beyond basic resolution.
- Browser Cache Pre-fetching: Once the malicious content is retrieved (e.g., from a TXT record or a linked resource), it is then staged using legitimate browser pre-fetching mechanisms. This allows the payload to be downloaded and stored in the browser’s cache without direct user interaction or overt network activity that might trigger alerts. This pre-staging sets the groundwork for later execution, making the attack appear less suspicious at the point of initial download.
Detection
Defenders can focus on identifying the underlying mechanisms used for evasion:
- Monitor DNS queries for unusual patterns, specifically requests for TXT records from domains not typically associated with legitimate TXT record usage (e.g., SPF, DKIM). Look for TXT records containing unusually long strings or base64-encoded data.
- Analyze network traffic for large or unusual data transfers via DNS, which could indicate payload exfiltration or delivery through TXT records.
- Inspect endpoint logs (e.g., Sysmon Event ID 22 for DNS queries) for suspicious processes (e.g.,
powershell.exe,cmd.exe,mshta.exe) making TXT record queries to external domains. - Monitor process creation events (e.g., Sysmon Event ID 1) for suspicious executables being launched by web browsers (
chrome.exe,firefox.exe,msedge.exe) or their child processes, which could indicate the execution of a pre-fetched payload.
Sigma Detection Rules
Suspicious Process Querying DNS TXT Record
title: Suspicious Process Querying DNS TXT Record
id: 9382b1c4-d5e7-4f1a-b8c3-f0a9e1e2f3g4
status: experimental
description: Detects suspicious processes making DNS TXT record queries, which can indicate payload retrieval or C2 activity via DNS.
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 22
QueryType: 'TXT'
Image|endswith:
- '\powershell.exe'
- '\cmd.exe'
- '\mshta.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection
level: high
Suspicious Process Creation by Web Browser
title: Suspicious Process Creation by Web Browser
id: 8a7b6c5d-4e3f-2a1b-0c9d-8e7f6a5b4c3d
status: experimental
description: Detects suspicious processes spawned by common web browsers, potentially indicating execution of a pre-fetched or downloaded malicious payload.
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
ParentImage|endswith:
- '\chrome.exe'
- '\firefox.exe'
- '\msedge.exe'
- '\iexplore.exe'
Image|endswith:
- '\powershell.exe'
- '\cmd.exe'
- '\mshta.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\regsvr32.exe'
- '\rundll32.exe'
- '\msiexec.exe'
condition: selection
level: high
Mitigations
- Enhanced DNS Monitoring and Filtering: Implement advanced DNS security solutions capable of inspecting DNS query content, including TXT records, for anomalies, embedded malicious data, or known malicious domains. Consider blocking TXT queries to non-standard or untrusted domains for non-DNS-related services.
- Network Traffic Analysis: Deploy network intrusion detection/prevention systems (NIDS/NIPS) with deep packet inspection to identify unusual protocols or data patterns over standard ports, especially DNS. Look for DNS traffic that deviates significantly from normal behavior in terms of size or frequency.
- Endpoint Security Configuration: Configure web browsers and endpoint security solutions to restrict or log pre-fetching activities, particularly from untrusted domains. Implement application control to prevent suspicious executables from launching from browser-related directories or temporary folders.
- User Awareness Training: Educate users about the risks of clicking suspicious links and the importance of verifying sources, as initial compromise might still leverage social engineering to direct users to malicious sites.
References
- https://www.darkreading.com/cyberattacks-data-breaches/clickfix-attacks-evolve-better-hide-malicious-payloads
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
T1071.004— DNST1027— Obfuscated Files or InformationT1105— Ingress Tool TransferT1562— Impair Defenses
Generated by
gemini-2.5-flash ·1,482 input / 1,508 output tokens ·
Reviewed and approved by a human analyst before publication