CyberSecurity SEE

ClickFix Transitions to Browser to Hijack Cryptocurrency

ClickFix Transitions to Browser to Hijack Cryptocurrency

ClickFix Campaign Evolves: From Tricking Users to Browser Manipulations

A recent report by Cisco Talos has shed light on an alarming shift in the modus operandi of the ClickFix campaign, which has transitioned from deceiving users into executing commands on their computers to encouraging them to inject malicious JavaScript directly into their browsers. This evolved strategy appears to target individuals inclined to engage in fraudulent activities, presenting a significant risk in the realm of cybersecurity.

According to Talos’s research, published on September 8, the ClickFix campaign has been utilizing the Google Visualization API to retrieve obfuscated code. This code is pulled from a publicly accessible Google Sheets document and then injected into user sessions on various cryptocurrency trading sites. This method not only disguises the malicious intent of the script but also makes it appear as legitimate web traffic since the requests originate from the victims’ own browsers.

Over the course of several months, the operation has proven remarkably resilient to efforts aimed at disruption. Talos had alerted both Google and the targeted trading platforms about the scheme in April; however, the campaign re-emerged just a week later with a new spreadsheet. As of August 11, despite additional reports concerning these substitute Google documents, they continued to remain active and operational.

Transition from Operating System to Browser

The ClickFix campaign first began to take shape in October 2025. Initially, the perpetrators lured potential victims by instructing them to paste JavaScript directly into the navigation bar of their Chrome browsers. A significant strategic shift occurred in March 2026, when the campaign operators began using the Google Visualization API in their tactics. By mid-April, victims were encouraged to install the Tampermonkey browser extension, which facilitated the addition of the injected script.

These lures often masqueraded as leaked vulnerability reports, falsely portraying fabricated API flaws in cryptocurrency swapping services. Promising payouts incredibly higher—up to 38%—these incentives attracted individuals eager to exploit supposed vulnerabilities without fully grasping the implications of their actions.

Talos reported finding a wealth of related material circulating on platforms like Telegram, the underground cybercrime forum DarkForums, and various text-sharing websites. This evidence indicated a sustained campaign, with updates and messages dispatched at least twice a month—a clear sign of the campaign’s calculated approach to target engagement.

Leveraging the Google Visualization API

The Google Visualization API serves as a critical tool in this scheme, providing free, unauthenticated access to any Google Sheets document made public on the web. As a result, the requests generated for nefarious purposes originate from the victims’ browsers, thereby blending seamlessly with ordinary web traffic. The attackers implemented clever formatting tricks, hiding the payload cells by rendering their text white on white, effectively disguising the harmful code within a benign-looking interface.

During the investigation, Talos collected a total of 21 different second-stage payloads sourced from the spreadsheet. These payloads showcased a rotation of fresh XOR keys and randomized variable names; however, the functionality of the scripts did not change significantly between versions.

Browser Scripts Function as Crypto Skimmers

Upon execution, the injected scripts transform the compromised browsers into sophisticated crypto skimming tools. These scripts are capable of monitoring page changes, misleadingly replacing displayed deposit addresses, and manipulating transaction amounts to create the illusion of a bonus addition. Additionally, they override the browser’s fetch API to substitute attacker-controlled wallet addresses into deposit responses before the users perceive any data on their screens.

An alarming facet of these scripts is their clipboard functionality, which systematically alters any cryptocurrency address that the victims copy. Within the Tampermonkey version of the attack, the code is designed to reload each time the targeted site is visited, ensuring continual fraud exposure for compromised users.

Throughout their examination, Talos identified 49 Bitcoin wallet addresses linked to the ClickFix campaign. An analysis of decoded samples from April through late June revealed that one specific set of 30 wallets facilitated funds to the tune of 0.159 BTC, roughly amounting to $10,000 based on valuations in early August. The researchers anticipate that the actual sum may be considerably higher. Proceeds appeared to have been funneled through 30 additional wallets before being distributed across more than 3,000 addresses, suggesting a sophisticated mixing strategy to obfuscate the trail of stolen funds.

Cisco Talos noted that while the campaign may not directly threaten the average organization, the techniques employed could pose broader implications. They advise restrictive measures regarding browser extensions based on user roles and recommend diligent monitoring of browser sessions for any requests originating from Google Docs—an essential step in mitigating the risks of such campaigns in the evolving landscape of cyber threats.

Source link

Exit mobile version