As cited
Copy frozen at (site build).
threat intel
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization application programming interface (API) for command and control, delivering obfuscated JavaScript from a publicly published Google Sheets document injected into victim browsers. The threat actors use social engineering variations of ClickFix, convincing targets to paste malicious code into Chrome's address bar or install it via the Tampermonkey browser extension. The injected script functions as a web skimmer, intercepting browser fetch requests, replacing cryptocurrency deposit addresses, and hijacking the clipboard to redirect funds to attacker-controlled wallets.
Why it matters: Cryptocurrency exchange users and e-commerce platforms are currently targeted, but the techniques could be repurposed for supply-chain attacks or broader web skimming operations affecting any organization relying on third-party JavaScript dependencies or vulnerable to ClickFix-style social engineering.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-theft campaign that abuses the Google Visualization application programming interface (API) for command and control, retrieving obfuscated JavaScript from publicly published Google Sheets documents and injecting it into victim browsers. Attackers use social engineering variations of ClickFix tactics, convincing targets to paste JavaScript into Chrome's address bar or install it in the Tampermonkey browser extension, while posing as leaked vulnerability reports for cryptocurrency swap services. The injected web skimmer hooks the browser's fetch API to replace legitimate cryptocurrency deposit addresses with attacker-controlled ones and manipulates transaction amounts.
Why it matters: Cryptocurrency traders and users of swap platforms face direct theft of funds through account hijacking and address replacement; organizations should recognize that the techniques, including Google service abuse for command and control and browser-based code injection, present broader risks for supply-chain attacks and web application compromise affecting enterprise systems.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-theft campaign that abuses the Google Visualization application programming interface (API) for command and control, retrieving obfuscated JavaScript from publicly published Google Sheets documents and injecting it into victim browsers. Attackers use social engineering variations of ClickFix tactics, convincing targets to paste JavaScript into Chrome's address bar or install it in the Tampermonkey browser extension, while posing as leaked vulnerability reports for cryptocurrency swap services. The injected web skimmer hooks the browser's fetch API to replace legitimate cryptocurrency deposit addresses with attacker-controlled ones and manipulates transaction amounts.
Why it matters: Cryptocurrency traders and users of swap platforms face direct theft of funds through account hijacking and address replacement; organizations should recognize that the techniques, including Google service abuse for command and control and browser-based code injection, present broader risks for supply-chain attacks and web application compromise affecting enterprise systems.
- Source published
- First seen by Cybersecurity Tracker