ClickFix Moves into the Browser: Google Sheets C2 Steals Cryptocurrency

ClickFix browser attack using Google Sheets Visualization API as C2 to steal cryptocurrency
Instructions to activate the “zero day” in the first version of the lure document

ClickFix has abandoned its habit of knocking at PowerShell and has taken up residence directly inside the browser. Cisco Talos has disclosed a campaign in which the victim is invited to paste JavaScript into Chrome’s address bar or to install it via Tampermonkey. Once executed, the code operates within the page itself and requires no separate malicious program on the system.

The lure was dressed up as a supposedly leaked vulnerability report concerning a flaw in cryptocurrency swap services. The document promised roughly 38% higher payouts on SwapZone and, in a later revision, a 25% bonus on SimpleSwap. Links were disseminated through Telegram, DarkForums, and text-sharing sites, casting for users willing to exploit an invented flaw for quick profit.

How the Attack Evolved

The first variant instructed victims to paste a snippet prefixed with “javascript:” directly into Chrome. The attackers later migrated to Tampermonkey, which runs the script automatically on every visit to the targeted site. The second-stage payload was fetched from Google Sheets through the Visualization API. The use of Google services as a command-and-control channel is a technique first observed in banking trojan campaigns as far back as 2017.

The loaded JavaScript functions as a web skimmer. The script hooks the browser’s fetch API, replaces cryptocurrency deposit addresses in both site responses and the clipboard, and overlays counterfeit interface elements advertising a “bonus.” Talos identified 49 Bitcoin wallet addresses associated with the campaign; 24 of them received a combined 0.159 BTC, worth approximately $10,000 at early August 2026 exchange rates.

Difficult to Shut Down

The operation proved hard to disrupt. Talos alerted Google and the two affected services in April, after which the lure and C2 documents were blocked. Roughly a week later, the attackers returned with a fresh Google Sheets file. In July they relocated additional components into Google Docs and Sheets. As of August 11, some documents remained accessible despite repeated complaints.

ClickFix continues to evolve alongside browser defenses. In July, uBlock Origin began blocking part of the known infrastructure for such attacks. At the same time, Palo Alto Networks counted more than 84,000 sites hosting various ClickFix variants in its own browser-threat analysis.

Broader Implications and Defense Guidance

Talos warns that the browser-based technique could be transplanted from cryptocurrency theft to web applications and supply chains, though no such attacks were recorded in this report. For defense, the firm recommends restricting browser extensions and developer-level features by role, monitoring unusual requests to docs.google.com, and auditing third-party JavaScript within enterprise web applications.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply