Skip to content
Cisco Talos Reports ClickFix Attacks Targeting Cryptocurrency Traders

Cisco Talos Reports ClickFix Attacks Targeting Cryptocurrency Traders

First seen 7 Oct 2026, 17:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 20:32 UTC
  • •Two ClickFix attack campaigns identified targeting cryptocurrency traders.
  • •Victims are tricked into executing malicious JavaScript via trusted services.
  • •Cisco recommends strengthening browser controls and user education.

Cisco Talos has identified two ClickFix attack campaigns that exploit trusted services to deceive victims into executing malicious code. The first campaign, active since October 2025, targets cryptocurrency traders with fake security reports, leading them to paste JavaScript into their browsers, which then retrieves attack code from a Google spreadsheet. This malware can alter cryptocurrency deposit addresses and has been linked to over $10,000 in Bitcoin theft across 49 addresses. The second campaign, observed in April 2026, uses fraudulent Google verification prompts from a compromised site, resulting in the installation of the Amatera information stealer, which can harvest credentials and cryptocurrency. Cisco advises organizations to enhance browser controls and educate users about legitimate verification processes. The attacks leverage familiar online experiences, making detection challenging.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-10-01
First ClickFix campaign launched
Attackers began targeting cryptocurrency traders with fake security reports, leading to JavaScript execution.
Scworld
2026-04-01
Second ClickFix campaign observed
A fake Google verification prompt was used to install the Amatera information stealer on victims' devices.
Scworld

More articles in this cluster (2)

Following this threat?

Track ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How do ClickFix attacks work?
ClickFix attacks trick victims into executing malicious code by leveraging trusted services, making detection difficult.
What should organizations do to protect themselves?
Organizations should strengthen browser controls, monitor application requests, and educate users about legitimate verification processes.
Who is primarily targeted by these attacks?
The primary targets of these ClickFix attacks are cryptocurrency traders.