THREAT OPS › Threat News › ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
<ul><li>Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. </li><li>The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands agai
MITRE ATT&CK techniques
Indicators of compromise
- https://www.proofpoint.com/us/blog/threat-insight/clipboard-compromise-powershell-self-pwnurl
- https://bolster.ai/blog/swapzone-profit-trick-web-inject-from-lure-to-live-dom-hijackurl
- https://developers.googleblog.com/introducing-the-google-visualization-api/url
- https://www.sophos.com/en-us/blog/phishing-and-malware-actors-abuse-google-forms-for-credentials-data-exfiltrationurl
- https://www.tampermonkey.net/url
- https://paste.sh/dQfdExjo#AqjB4BBturl
- https://www.malwarebytes.com/blog/news/2026/01/online-shoppers-at-risk-as-magecart-skimming-hits-major-payment-networksurl
- storage.ghost.iodomain
- pastebin.comdomain
- swapzone.iodomain
- simpleswap.iodomain
- obfuscator.iodomain
Original source: https://blog.talosintelligence.com/clickfix-moves-into-the-browser/