CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6642

As cited

Copy frozen at (site build).

threat intel

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization application programming interface (API) for command and control, delivering obfuscated JavaScript from a publicly published Google Sheets document injected into victim browsers. The threat actors use social engineering variations of ClickFix, convincing targets to paste malicious code into Chrome's address bar or install it via the Tampermonkey browser extension. The injected script functions as a web skimmer, intercepting browser fetch requests, replacing cryptocurrency deposit addresses, and hijacking the clipboard to redirect funds to attacker-controlled wallets.

Why it matters: Cryptocurrency exchange users and e-commerce platforms are currently targeted, but the techniques could be repurposed for supply-chain attacks or broader web skimming operations affecting any organization relying on third-party JavaScript dependencies or vulnerable to ClickFix-style social engineering.

VendorsGoogleCiscoAdobe
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos is tracking a cryptocurrency-theft campaign that abuses the Google Visualization application programming interface (API) for command and control, retrieving obfuscated JavaScript from publicly published Google Sheets documents and injecting it into victim browsers. Attackers use social engineering variations of ClickFix tactics, convincing targets to paste JavaScript into Chrome's address bar or install it in the Tampermonkey browser extension, while posing as leaked vulnerability reports for cryptocurrency swap services. The injected web skimmer hooks the browser's fetch API to replace legitimate cryptocurrency deposit addresses with attacker-controlled ones and manipulates transaction amounts.

Why it matters: Cryptocurrency traders and users of swap platforms face direct theft of funds through account hijacking and address replacement; organizations should recognize that the techniques, including Google service abuse for command and control and browser-based code injection, present broader risks for supply-chain attacks and web application compromise affecting enterprise systems.

VendorsGoogleCiscoAdobe
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos is tracking a cryptocurrency-theft campaign that abuses the Google Visualization application programming interface (API) for command and control, retrieving obfuscated JavaScript from publicly published Google Sheets documents and injecting it into victim browsers. Attackers use social engineering variations of ClickFix tactics, convincing targets to paste JavaScript into Chrome's address bar or install it in the Tampermonkey browser extension, while posing as leaked vulnerability reports for cryptocurrency swap services. The injected web skimmer hooks the browser's fetch API to replace legitimate cryptocurrency deposit addresses with attacker-controlled ones and manipulates transaction amounts.

Why it matters: Cryptocurrency traders and users of swap platforms face direct theft of funds through account hijacking and address replacement; organizations should recognize that the techniques, including Google service abuse for command and control and browser-based code injection, present broader risks for supply-chain attacks and web application compromise affecting enterprise systems.

VendorsGoogleCiscoAdobe
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary