HIGHmalware·

ClickFix Attacks Evolve to Leverage DNS TXT Records and Browser Pre-fetching for Payload Hiding

ClickFix attacks are evolving to evade detection by using DNS TXT records to hide malicious payloads and browser cache pre-fetching to stage them. This sophisticated technique makes early-stage attack identification more challenging for defenders, as it obscures the initial delivery mechanisms.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

ClickFix attacks have adopted new evasion techniques, specifically leveraging DNS TXT records for payload storage and browser cache pre-fetching for staging. This evolution aims to obscure the initial stages of the attack chain, making it harder for security tools to identify and block malicious activity before execution. The techniques allow threat actors to bypass traditional network filtering and detection mechanisms focused on common payload delivery protocols.

Technical Analysis

Threat actors are enhancing ClickFix attacks by employing two primary methods to hide and stage malicious payloads:

  • Payload Hiding via DNS TXT Records: Malicious code, URLs, or command-and-control (C2) instructions are embedded within DNS TXT records. When a victim’s system resolves a specific domain, it retrieves the TXT record, which then contains the hidden payload or a pointer to it. This method allows for data exfiltration or ingress tool transfer over DNS, bypassing network defenses that might not inspect DNS query content beyond basic resolution.
  • Browser Cache Pre-fetching: Once the malicious content is retrieved (e.g., from a TXT record or a linked resource), it is then staged using legitimate browser pre-fetching mechanisms. This allows the payload to be downloaded and stored in the browser’s cache without direct user interaction or overt network activity that might trigger alerts. This pre-staging sets the groundwork for later execution, making the attack appear less suspicious at the point of initial download.

Detection

Defenders can focus on identifying the underlying mechanisms used for evasion:

  • Monitor DNS queries for unusual patterns, specifically requests for TXT records from domains not typically associated with legitimate TXT record usage (e.g., SPF, DKIM). Look for TXT records containing unusually long strings or base64-encoded data.
  • Analyze network traffic for large or unusual data transfers via DNS, which could indicate payload exfiltration or delivery through TXT records.
  • Inspect endpoint logs (e.g., Sysmon Event ID 22 for DNS queries) for suspicious processes (e.g., powershell.exe, cmd.exe, mshta.exe) making TXT record queries to external domains.
  • Monitor process creation events (e.g., Sysmon Event ID 1) for suspicious executables being launched by web browsers (chrome.exe, firefox.exe, msedge.exe) or their child processes, which could indicate the execution of a pre-fetched payload.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

Suspicious Process Querying DNS TXT Record

title: Suspicious Process Querying DNS TXT Record
id: 9382b1c4-d5e7-4f1a-b8c3-f0a9e1e2f3g4
status: experimental
description: Detects suspicious processes making DNS TXT record queries, which can indicate payload retrieval or C2 activity via DNS.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 22
    QueryType: 'TXT'
    Image|endswith:
      - '\powershell.exe'
      - '\cmd.exe'
      - '\mshta.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
  condition: selection
level: high

Suspicious Process Creation by Web Browser

title: Suspicious Process Creation by Web Browser
id: 8a7b6c5d-4e3f-2a1b-0c9d-8e7f6a5b4c3d
status: experimental
description: Detects suspicious processes spawned by common web browsers, potentially indicating execution of a pre-fetched or downloaded malicious payload.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 1
    ParentImage|endswith:
      - '\chrome.exe'
      - '\firefox.exe'
      - '\msedge.exe'
      - '\iexplore.exe'
    Image|endswith:
      - '\powershell.exe'
      - '\cmd.exe'
      - '\mshta.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\regsvr32.exe'
      - '\rundll32.exe'
      - '\msiexec.exe'
  condition: selection
level: high

Mitigations

  1. Enhanced DNS Monitoring and Filtering: Implement advanced DNS security solutions capable of inspecting DNS query content, including TXT records, for anomalies, embedded malicious data, or known malicious domains. Consider blocking TXT queries to non-standard or untrusted domains for non-DNS-related services.
  2. Network Traffic Analysis: Deploy network intrusion detection/prevention systems (NIDS/NIPS) with deep packet inspection to identify unusual protocols or data patterns over standard ports, especially DNS. Look for DNS traffic that deviates significantly from normal behavior in terms of size or frequency.
  3. Endpoint Security Configuration: Configure web browsers and endpoint security solutions to restrict or log pre-fetching activities, particularly from untrusted domains. Implement application control to prevent suspicious executables from launching from browser-related directories or temporary folders.
  4. User Awareness Training: Educate users about the risks of clicking suspicious links and the importance of verifying sources, as initial compromise might still leverage social engineering to direct users to malicious sites.

References

  • https://www.darkreading.com/cyberattacks-data-breaches/clickfix-attacks-evolve-better-hide-malicious-payloads

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,482 input / 1,508 output tokens ·
Reviewed and approved by a human analyst before publication
#malware#browser#dns#evasion#high#malware#web