talos · Crawled Sep 8, 2026

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

5 IoCs
Read original article ↗

AI Summary

Cisco Talos identified a cryptocurrency theft campaign dubbed ClickFix that abuses legitimate services, particularly the Google Visualization API, for command and control (C2). The attackers use social engineering to trick victims into pasting malicious JavaScript into their browser or installing it via the Tampermonkey browser extension, enabling persistent access. The malicious script acts as a web skimmer, intercepting and altering cryptocurrency deposit addresses in real time, hijacking clipboard content, and injecting fake UI elements to deceive users into believing they are receiving transaction bonuses. The campaign primarily targets cryptocurrency traders through lures distributed on Telegram, DarkForums, and paste sites, using Google Sheets to host obfuscated payloads and evade detection.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Domain paste[.]sh Details →
Domain swapzone[.]io Details →
Domain simpleswap[.]io Details →
GitHub Repo talosintelligence/iocs Details →
Filename API Logic Flaw Details →