ClickFix adopts browser injection to steal cryptocurrency
A ClickFix campaign is manipulating cryptocurrency users into injecting malicious JavaScript directly into their browsers, allowing attackers to replace legitimate wallet addresses and divert transfers, Cisco Talos has disclosed. The campaign marks a shift from familiar ClickFix attacks that persuade victims to run PowerShell, Terminal or other operating-system commands. Instead, targets are…
A ClickFix operation is targeting cryptocurrency users by injecting malicious JavaScript code directly into their browsers. This allows attackers to manipulate wallet addresses and redirect cryptocurrency transfers. Researchers from Cisco Talos have discovered this shift from previous ClickFix attacks, which typically involve users running commands in operating systems like PowerShell or Terminal.
Instead, this new campaign tricks targets into pasting code into the Chrome address bar or installing it via the Tampermonkey browser extension. Google's Visualization API is used to retrieve obfuscated JavaScript from publicly accessible Google Sheets. This makes the command-and-control traffic appear more legitimate, as it appears to originate from a regular browser session to a trusted Google domain.
The operation presents itself as a leaked vulnerability report for a non-existent flaw in cryptocurrency swap services, promising users unusually high returns for activating the supposed exploit. This lure targets individuals on cryptocurrency, software development, cybersecurity, and hacking forums who might be tempted to exploit a purported technical weakness for financial gain.
The campaign has been distributed through Telegram, DarkForums, Pastebin comments, and other text-sharing sites. Two variants have been observed, targeting SwapZone.io and SimpleSwap.io, with false claims of exposed APIs and alleged high returns. Once installed, the Tampermonkey extension causes the malicious code to execute each time the user opens the targeted cryptocurrency site.
The second-stage payload functions as a web skimmer, monitoring page changes, manipulating displayed interfaces, and intercepting network responses. It overrides the browser's fetch function to identify cryptocurrency deposit information and replace it with attacker-controlled addresses before the victim completes a transfer. The script also hijacks clipboard activity, replacing copied deposit addresses with attacker-controlled Bitcoin addresses.
This altered information is then displayed on the manipulated page, appearing consistent with the false promises offered by the lure. Talos has collected 21 distinct second-stage payload samples and identified 49 Bitcoin addresses associated with the campaign. Of 30 addresses repeatedly embedded in samples, 24 received funds, totaling 0.159 Bitcoin, roughly $10,000 at early August valuations.
Despite attempts to obscure their destinations, funds were moved through complex transactions involving over 3,000 addresses. The campaign has shown resilience when individual components were blocked. After sharing information with Google and targeted services in April, the operators returned with new Google Sheets and replacement scripts.
In July, the attackers shifted delivery methods to Google Docs, where the script material is now hosted. Google-hosted documents connected to the operation have been reported through multiple channels. This technique emerged from activity dating back to October 2025, with the use of Google's Visualization API observed from March.
By July, the operators had consolidated all principal campaign components into Google Docs and Sheets, reducing reliance on disposable external hosting.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.