Close Menu
إستثمار
    الأكثر مشاهدة

    Cisco Talos Reveals How ClickFix Campaigns Are Hiding Malicious Activity in Trusted Platforms

    English News

    تمويلات “كفاءة المالية” للمشاريع تناهز 100 مليون ريال

    مال و أعمال

    ASB Capital Partners with StepStone in Launching a Private Markets Offering: ASB StepStone Private Financing Fund

    موضة وأزياء
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    إستثمار
    • الرئيسية
    • رئيسي
    • أخبار عامة
    • أسهم
    • English News
    • سياحة وسفر
    • سيارات
    • عقارات
    • مال و أعمال
    • مقالات
    إستثمار
    الرئيسية»English News»Cisco Talos Reveals How ClickFix Campaigns Are Hiding Malicious Activity in Trusted Platforms

    Cisco Talos Reveals How ClickFix Campaigns Are Hiding Malicious Activity in Trusted Platforms

    Facebook Twitter LinkedIn WhatsApp Email
    مشاركة
    Facebook Twitter LinkedIn Email WhatsApp

     Cisco Talos, Cisco’s threat intelligence organization, has published findings from two investigations into ClickFix attacks, a technique that persuades victims to copy and run malicious code on their own computers

    The investigations show how attackers are using services that organizations already trust and allow through their networks to conceal malicious activity. In one campaign, cryptocurrency traders were persuaded to paste code into Chrome that retrieved the main attack code from a public Google spreadsheet. In a separate campaign, a fake Google verification prompt led to stolen credentials, cryptocurrency theft and remote access to compromised machines

    “Attackers are increasingly finding ways to hide malicious activity within trusted services and familiar online experiences, making it more difficult to distinguish malicious behavior from legitimate activity,” said Fady Younes, Managing Director, Cybersecurity, Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia (METAC) at Cisco. “Organizations should look beyond whether a destination itself is trusted and focus on which applications are making requests, strengthen controls around browsers and extensions and reinforce awareness around prompts asking users to copy and run commands on their devices”

    Example One: A cryptocurrency scam leveraging Google Sheets

    The first campaign has been operating since October 2025 and targets cryptocurrency traders. The bait is a fake leaked security report claiming a vulnerability at two currency swap sites could provide a bonus of 25% or more. Talos identified the lure circulating across Telegram, criminal forums and text-sharing sites.

    Victims are instructed to paste JavaScript into the Chrome address bar or add it to a legitimate browser extension so that it reloads on every visit. The pasted code then retrieves the main malicious payload from a publicly published Google spreadsheet, where the operators concealed the code using white text on a white background.

    The resulting malware can rewrite the cryptocurrency deposit address displayed on a trading page, replace addresses copied by the victim and display a convincing fake bonus on screen.

    Talos traced 49 Bitcoin addresses associated with the campaign, 24 of which collected victim funds worth at least approximately US$10,000 before the funds were moved through more than 3,000 additional addresses. Talos notes that the actual figure is likely higher because samples from the earliest phase of the campaign were unavailable.

    After Talos shared its findings with Google and the affected sites in April 2026, the identified lure and control documents were removed. Approximately one week later, the campaign resumed using a new spreadsheet, with later versions remaining active into August despite being repeatedly flagged.

    Example Two: Fake verification prompts lead to credential theft and remote access

    The second investigation began in April 2026 after Talos observed unusual activity at a European government organization. Talos assesses with moderate confidence that the activity formed part of a broader cryptocurrency and credential theft operation rather than an attack specifically targeting that organization.

    In this campaign, malicious code planted on a compromised website, in an infection chain linked to ClearFake, retrieves its next instructions from a public blockchain. Victims are then presented with a fake Google CAPTCHA and instructed to paste a command into Windows.

    The command installs the Amatera information stealer, which can harvest browser data, messaging applications, more than 100 cryptocurrency wallets, password managers and files containing private keys.

    Follow-on payloads can also disable security software, turn the compromised machine into a relay for attacker traffic and install a hidden copy of commercial remote support software.

    Strengthening defenses against ClickFix attacks

    Cisco Talos highlights several steps organizations can take to reduce exposure to these techniques.

    Organizations should manage browsers with the same level of control applied to laptops, including controlling which extensions employees can install. Security teams should also monitor requests to cloud collaboration services from applications or browser sessions that have no reason to make them and review third-party components running on customer-facing websites for unusual activity.

    Organizations can also reinforce employee awareness with a simple principle: legitimate verification processes should not require users to copy a command and manually run it on their device.

    Both Cisco Talos reports include detection guidance and technical indicators for security teams

    مشاركة. Facebook Twitter LinkedIn WhatsApp Email
    المقالة السابقةتمويلات “كفاءة المالية” للمشاريع تناهز 100 مليون ريال
    admin
    • الموقع الالكتروني

    إقرأ أيضا

    English News

    Women Shaping Wealth Summit Positions Riyadh as a Global Meeting Point for Women and Capital

    English News
    English News

    Experts Gather to Highlight Latest Scientific Development to Improve the Quality of Life for Individuals with Achondroplasia

    English News
    English News

    CATRION Strengthens Sustainability Leadership with Three Wins at the Gulf Sustainability Awards 2026

    English News
    English News

    Al Salam Bank and J.P. Morgan Payments Feature Overnight Murabaha Liquidity Solution

    English News
    اترك تعليقك إلغاء الرد

    مختارات
    إقرأ أيضا
    English News

    Cisco Talos Reveals How ClickFix Campaigns Are Hiding Malicious Activity in Trusted Platforms

     Cisco Talos, Cisco’s threat intelligence organization, has published findings from two investigations into ClickFix attacks,…

    تمويلات “كفاءة المالية” للمشاريع تناهز 100 مليون ريال

    مال و أعمال

    ASB Capital Partners with StepStone in Launching a Private Markets Offering: ASB StepStone Private Financing Fund

    موضة وأزياء

    شركة (ASB Capital) تتعاون مع (StepStone) لإطلاق منتجها الاستثماري في الأسواق الخاصة عبر صندوق ASB StepStone للتمويل الخاص

    موضة وأزياء

    منصة إخبارية تلتزم بمعايير الدقة والحيادية والموضوعية من خلال تغطية دقيقة للأحداث،تهتم بمنطقة الشرق الأوسط خاصة دول الخليج العربي.

    راسلنا عبر البريد الالكتروني : info@blog.yoszero.online

    تصنيفات
    • English News
    • News English
    • أخبار عامة
    • أسهم
    • اخبار
    • اخبار عامه
    • اقتصاد
    • تجاره وأعمال
    • ترفيه وفعاليات
    • تقنية
    • تكنولوجيا و اتصالات
    • رئيسي
    • رياضة
    • سياحة وسفر
    • سيارات
    • صحة
    • صحة و جمال
    • صحة وجمال
    • عقارات
    • علوم وتكنولوجيا
    • فيديو
    • مال و أعمال
    • مقالات
    • موضة وأزياء
    تابع أيضا

    إطلاق علاج فولفورمر  Volformer وألترافورمر Ultraformer المتطور لشد البشرة وتعزيز تماسكها في عيادة أثينا للأمراض الجلدية

    صحة

    نيسان وهوندا تبرمان اتفاقية تطوير مشترك

    سيارات

    سمير عباس : تطور الوعي خلال ٥٠ عاما مضت ساهم في علاجات الذكورة دون صمت

    صحة
    إستثمار
    Facebook X (Twitter) Instagram
    • الرئيسية
    • صحة
    • سيارات
    • رياضة
    2026 © كل الحقوق محفوظة

    اكتب كلمة البحث أو اضغط Esc لإلغاء شاشة البحث