Cisco Talos, Cisco’s threat intelligence organization, has published findings from two investigations into ClickFix attacks, a technique that persuades victims to copy and run malicious code on their own computers

The investigations show how attackers are using services that organizations already trust and allow through their networks to conceal malicious activity. In one campaign, cryptocurrency traders were persuaded to paste code into Chrome that retrieved the main attack code from a public Google spreadsheet. In a separate campaign, a fake Google verification prompt led to stolen credentials, cryptocurrency theft and remote access to compromised machines

“Attackers are increasingly finding ways to hide malicious activity within trusted services and familiar online experiences, making it more difficult to distinguish malicious behavior from legitimate activity,” said Fady Younes, Managing Director, Cybersecurity, Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia (METAC) at Cisco. “Organizations should look beyond whether a destination itself is trusted and focus on which applications are making requests, strengthen controls around browsers and extensions and reinforce awareness around prompts asking users to copy and run commands on their devices”

Example One: A cryptocurrency scam leveraging Google Sheets

The first campaign has been operating since October 2025 and targets cryptocurrency traders. The bait is a fake leaked security report claiming a vulnerability at two currency swap sites could provide a bonus of 25% or more. Talos identified the lure circulating across Telegram, criminal forums and text-sharing sites.

Victims are instructed to paste JavaScript into the Chrome address bar or add it to a legitimate browser extension so that it reloads on every visit. The pasted code then retrieves the main malicious payload from a publicly published Google spreadsheet, where the operators concealed the code using white text on a white background.

The resulting malware can rewrite the cryptocurrency deposit address displayed on a trading page, replace addresses copied by the victim and display a convincing fake bonus on screen.

Talos traced 49 Bitcoin addresses associated with the campaign, 24 of which collected victim funds worth at least approximately US$10,000 before the funds were moved through more than 3,000 additional addresses. Talos notes that the actual figure is likely higher because samples from the earliest phase of the campaign were unavailable.

After Talos shared its findings with Google and the affected sites in April 2026, the identified lure and control documents were removed. Approximately one week later, the campaign resumed using a new spreadsheet, with later versions remaining active into August despite being repeatedly flagged.

Example Two: Fake verification prompts lead to credential theft and remote access

The second investigation began in April 2026 after Talos observed unusual activity at a European government organization. Talos assesses with moderate confidence that the activity formed part of a broader cryptocurrency and credential theft operation rather than an attack specifically targeting that organization.

In this campaign, malicious code planted on a compromised website, in an infection chain linked to ClearFake, retrieves its next instructions from a public blockchain. Victims are then presented with a fake Google CAPTCHA and instructed to paste a command into Windows.

The command installs the Amatera information stealer, which can harvest browser data, messaging applications, more than 100 cryptocurrency wallets, password managers and files containing private keys.

Follow-on payloads can also disable security software, turn the compromised machine into a relay for attacker traffic and install a hidden copy of commercial remote support software.

Strengthening defenses against ClickFix attacks

Cisco Talos highlights several steps organizations can take to reduce exposure to these techniques.

Organizations should manage browsers with the same level of control applied to laptops, including controlling which extensions employees can install. Security teams should also monitor requests to cloud collaboration services from applications or browser sessions that have no reason to make them and review third-party components running on customer-facing websites for unusual activity.

Organizations can also reinforce employee awareness with a simple principle: legitimate verification processes should not require users to copy a command and manually run it on their device.

Both Cisco Talos reports include detection guidance and technical indicators for security teams

مشاركة.
اترك تعليقك

Exit mobile version