Back Infosecurity-Magazine ClickFix Moves into the Browser to Steal Cryptocurrency
A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject malicious JavaScript into their own browsers, in a scheme aimed at people willing to commit fraud.
Cisco Talos said in research published September 8 that the months-long campaign used the Google Visualization API to retrieve obfuscated code from a public Google Sheets document and inject it into sessions on two cryptocurrency trading sites.
The operation has survived two disruption attempts. Talos alerted Google and the targeted sites in April, and the campaign returned a week later on a new spreadsheet; as of August 11 the replacement Google documents had been reported again but remained live.
ClickFix Moves From the OS to the Browser
The campaign began in October 2025 with lures instructing targets to paste JavaScript into Chrome's bar. The operators added the Visualization API in March 2026 and, from mid-April, told victims to install the Tampermonkey browser extension before adding a script.
The lures posed as leaked vulnerability reports describing non-existent API flaws at cryptocurrency swap services, promising payouts up to 38% higher. Talos said the appeal was to readers prepared to exploit a flaw they did not understand.
Talos found the material on Telegram, the cybercrime forum DarkForums and text-sharing sites, with waves of messages sent at least twice a month.
The Visualization API gives free, unauthenticated read-only access to any Google Sheets document published to the web, so the request came from the victim's own browser and resembled ordinary web traffic. The operators hid the payload cells by formatting the text white on white.
Talos collected 21 second-stage payloads from the spreadsheet, rotated with fresh XOR keys and randomized variable names but functionally unchanged.
Injected Scripts Turn Browser Into Crypto Skimmer
The scripts monitored page changes, replaced displayed deposit addresses and altered transaction amounts to suggest a bonus had been applied. They also overrode the browser's fetch API, substituting attacker wallet addresses into deposit responses before the data reached the page.
A clipboard function replaced any address the victim copied. On the Tampermonkey version, the code reloaded on every visit to the targeted site.
Talos identified 49 Bitcoin addresses across the campaign. Most samples it decoded, covering April to late June, drew on one set of 30, of which 24 received victim funds totaling 0.159 BTC, $10,000 at early August valuations.
The researchers said the real figure was probably higher, and that proceeds were routed through 30 further wallets and then more than 3000 addresses in what looked like a mixing operation.
Talos said the campaign posed no specific threat to most organizations but that the techniques did, and advised restricting browser extensions by role and monitoring browser sessions for requests to Google Docs.
New SilabRAT Trojan Hijacks Sessions to Steal Crypto News 10 June 2026
New SilabRAT Trojan Hijacks Sessions to Steal Crypto
New Venom Stealer MaaS Platform Automates Continuous Data Theft News 1 April 2026
New Venom Stealer MaaS Platform Automates Continuous Data Theft
FileFix Campaign Using Steganography and Multistage Payloads News 17 September 2025
FileFix Campaign Using Steganography and Multistage Payloads
Browser-Based Cyber-Threats Surge as Email Malware Declines News 14 January 2025
Browser-Based Cyber-Threats Surge as Email Malware Declines
New Malware WarmCookie Targets Users with Malicious Links News 23 October 2024
New Malware WarmCookie Targets Users with Malicious Links
What’s Hot on Infosecurity Magazine?
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
NCSC Warns Shadow AI Creates New Security Risks
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
Multiple Class Action Lawsuits Filed Against IDScan
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
NCSC Warns Shadow AI Creates New Security Risks
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
How to Manage Enterprise Cyber Resilience in the Age of AI
How to Harness Advanced Intelligence Capabilities to Strengthen Cyber Defence
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
