THREATOPS
THREAT OPSThreat News › ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

medtalosPublished 2026-09-08

<ul><li>Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim&apos;s browser session.&#xa0;</li><li>The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands agai

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://blog.talosintelligence.com/clickfix-moves-into-the-browser/