ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
AI Summary
Cisco Talos identified a cryptocurrency theft campaign dubbed ClickFix that abuses legitimate services, particularly the Google Visualization API, for command and control (C2). The attackers use social engineering to trick victims into pasting malicious JavaScript into their browser or installing it via the Tampermonkey browser extension, enabling persistent access. The malicious script acts as a web skimmer, intercepting and altering cryptocurrency deposit addresses in real time, hijacking clipboard content, and injecting fake UI elements to deceive users into believing they are receiving transaction bonuses. The campaign primarily targets cryptocurrency traders through lures distributed on Telegram, DarkForums, and paste sites, using Google Sheets to host obfuscated payloads and evade detection.
AI-extracted · verify before operational use