Blog.Talosintelligence
New ClickFix Campaign Exploits Google Services for Cryptocurrency Theft
Article Content
Cisco Talos has identified a cryptocurrency theft campaign that leverages the Google Visualization API to inject malicious JavaScript into victims' browsers. The attackers use social engineering tactics, convincing users to paste code into their browser or install it via the Tampermonkey extension. This campaign, which began in October 2025, has evolved to utilize Google Sheets for command and control, targeting cryptocurrency traders and developers. The injected scripts act as web skimmers, altering cryptocurrency deposit addresses and stealing sensitive information. While the campaign primarily affects individual users, its techniques pose a broader threat to organizations due to the abuse of legitimate services. The attackers have been distributing lures through Telegram and DarkForums, exploiting the promise of nonexistent API vulnerabilities. Current observations indicate that the campaign is ongoing and evolving.
Key Points: • Attackers exploit Google services to inject malicious JavaScript into browsers. • Campaign targets cryptocurrency traders using social engineering tactics. • Malicious scripts alter transaction details and steal sensitive information.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.