Skip to content
ClickFix Moves into the Browser to Steal Cryptocurrency

ClickFix Moves into the Browser to Steal Cryptocurrency

Infosecurity-Magazine September 9, 2026

A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject malicious JavaScript into their own browsers, in a scheme aimed at people willing to commit fraud.

Cisco Talos said in research published September 8 that the months-long campaign used the Google Visualization API to retrieve obfuscated code from a public Google Sheets document and inject it into sessions on two cryptocurrency trading sites.

The operation has survived two disruption attempts. Talos alerted Google and the targeted sites in April, and the campaign returned a week later on a new spreadsheet; as of August 11 the replacement Google documents had been reported again but remained live.

ClickFix Moves From the OS to the Browser

The campaign began in October 2025 with lures instructing targets to paste JavaScript into Chrome's bar. The operators added the Visualization API in March 2026 and, from mid-April, told victims to install the Tampermonkey browser extension before adding a script.

The lures posed as leaked vulnerability reports describing non-existent API flaws at cryptocurrency swap services, promising payouts up to 38% higher. Talos said the appeal was to readers prepared to exploit a flaw they did not understand.

Talos found the material on Telegram, the cybercrime forum DarkForums and text-sharing sites, with waves of messages sent at least twice a month.

The Visualization API gives free, unauthenticated read-only access to any Google Sheets document published to the web, so the request came from the victim's own browser and resembled ordinary web traffic. The operators hid the payload cells by formatting the text white on white.

Talos collected 21 second-stage payloads from the spreadsheet, rotated with fresh XOR keys and randomized variable names but functionally unchanged.

Injected Scripts Turn Browser Into Crypto Skimmer

The scripts monitored page changes, replaced displayed deposit addresses and altered transaction amounts to suggest a bonus had been applied. They also overrode the browser's fetch API, substituting attacker wallet addresses into deposit responses before the data reached the page.

A clipboard function replaced any address the victim copied. On the Tampermonkey version, the code reloaded on every visit to the targeted site.

Talos identified 49 Bitcoin addresses across the campaign. Most samples it decoded, covering April to late June, drew on one set of 30, of which 24 received victim funds totaling 0.159 BTC, $10,000 at early August valuations.

The researchers said the real figure was probably higher, and that proceeds were routed through 30 further wallets and then more than 3000 addresses in what looked like a mixing operation.

Talos said the campaign posed no specific threat to most organizations but that the techniques did, and advised restricting browser extensions by role and monitoring browser sessions for requests to Google Docs.

New SilabRAT Trojan Hijacks Sessions to Steal Crypto News 10 June 2026

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

New Venom Stealer MaaS Platform Automates Continuous Data Theft News 1 April 2026

New Venom Stealer MaaS Platform Automates Continuous Data Theft

FileFix Campaign Using Steganography and Multistage Payloads News 17 September 2025

FileFix Campaign Using Steganography and Multistage Payloads

Browser-Based Cyber-Threats Surge as Email Malware Declines News 14 January 2025

Browser-Based Cyber-Threats Surge as Email Malware Declines

New Malware WarmCookie Targets Users with Malicious Links News 23 October 2024

New Malware WarmCookie Targets Users with Malicious Links

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

NCSC Warns Shadow AI Creates New Security Risks

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

Multiple Class Action Lawsuits Filed Against IDScan

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era

NCSC Warns Shadow AI Creates New Security Risks

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

How to Manage Enterprise Cyber Resilience in the Age of AI

How to Harness Advanced Intelligence Capabilities to Strengthen Cyber Defence

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust