ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Talos tracks a crypto-theft campaign abusing the Google Visualization API for C2, using browser-based ClickFix lures to inject web-skimmer JavaScript.
Criminal actors convinced targets to paste JavaScript into Chrome's address bar or install it in the Tampermonkey extension, injecting a web skimmer into sessions on two cryptocurrency trading websites; Tampermonkey also provides persistence. Since March 2026 the campaign retrieved obfuscated scripts via the Google Visualization API from public Google Sheets documents, hooking the fetch API and replacing cryptocurrency deposit addresses in responses and the clipboard. Lures pose as leaked reports of a nonexistent API flaw at cryptocurrency swap services and spread via Telegram, DarkForums, and paste sites since early October 2025. Talos warns the legitimate-service-abuse techniques could enable wider supply-chain attacks on e-commerce and customer-facing systems.
Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT
Cortex XDR threat hunters uncovered a phishing campaign delivering the NetSupport Manager RAT via a fake password-protected NortonLifelock Word document.
Unit 42 identified a January 2020 phishing campaign using a Microsoft Word document disguised as a password-protected NortonLifelock file. Enabling macros triggered an obfuscated command that built alpaca.bat in the temp directory, which used msiexec to download an MSI payload from quickwaysignstx.com, filtered on the Windows Installer user-agent string. The payload installed a PowerShell script and the campaign, which has delivered NetSupport Manager RAT since at least 2018, showed related activity dating back to early November 2019.
North Korean remote workers are broadening their job hunt beyond IT
Huntress links suspected North Korean remote workers to sales, marketing, and healthcare jobs using stolen identities, VPNs, proxies, and KVM hardware.
Huntress investigations identified suspected DPRK remote workers hired beyond IT in sales, marketing, and healthcare/financial organizations, sometimes actually performing the work they were hired for. Fraudulent documents included passports from the same city issued one day apart, ID cards with identical validity dates, and electricity bills built from the same online template with matching typos. A financial-services case found a PiKVM and Guermok USB capture card on a new hire's laptop within hours of delivery, suggesting a laptop farm, and another hire used a police mugshot with the photo digitally swapped. Researchers urge rigorous background checks and identity verification at the interview stage.
TrickBot Campaign Uses Fake Payroll Emails to Conduct Phishing Attacks
TrickBot phishing campaign used SendGrid, fake Google Docs, and Drive-hosted downloaders disguised as Word files to deliver a credential-stealing payload.
Unit 42 identified a TrickBot distribution campaign on November 7-8, 2019, using payroll and annual bonus-themed emails sent from likely compromised .edu addresses through the legitimate SendGrid email delivery service. Emails contained links to Google Docs documents linking to downloader executables hosted on Google Drive, further masked behind SendGrid click-tracking URLs. The downloaders, signed by PERISMOUNT LIMITED and displayed with Microsoft Word icons, show a decoy pop-up and retrieve TrickBot payloads from compromised legitimate domains such as savute[.]in and lindaspryinteriordesign[.]com. The newer TrickBot variant stores its files and configuration under %APPDATA%\cashcore.
Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cisco Talos details a crypto-theft ClickFix campaign abusing Google Sheets to swap wallet addresses, with about $10,000 in observed Bitcoin losses.
Cisco Talos tracks a ClickFix-style campaign that tricks cryptocurrency traders into pasting JavaScript into Chrome's address bar or a Tampermonkey extension, promising fake bonuses on SwapZone and SimpleSwap. The loader pulls obfuscated JavaScript from cells in a public Google Sheet via the Visualization API, then behaves like a web skimmer, rewriting deposit addresses on screen, in web responses, and in the clipboard. Researchers counted 49 attacker-controlled Bitcoin addresses, with 24 receiving a combined 0.159 BTC, roughly $10,000, by early August 2026. A Tampermonkey variant re-injects the payload on every return visit, giving the attackers persistence despite takedown efforts.
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
NovaCookies AitM phishing kit, a Sneaky 2FA variant, uses genuine Docusign lures to steal Microsoft 365 sessions at hundreds of organizations.
Island disclosed NovaCookies, a $320/month adversary-in-the-middle phishing-as-a-service platform that relays Microsoft 365 sign-ins through attacker infrastructure to capture credentials, MFA codes, and authenticated sessions. Campaigns abuse genuine Docusign envelopes and Microsoft/Google redirect hops so each step looks legitimate, with lure domains on .vu and alternating-case labels such as PwPt-sHaRe. Proofpoint assesses NovaCookies as a Sneaky 2FA variant with added flows for Okta and Entra domains federated to GoDaddy, and a fully managed PhaaS model. It has targeted hundreds of organizations in the U.S., U.K., Canada, Germany, Israel, and the U.A.E., and is advertised via Telegram with anti-analysis checks like a Cloudflare gate.
The sexy AI-powered dating app scams are here
Anthropic exposed a network of roughly 28 AI-driven dating apps using autonomous personas and gig workers to defraud paying users.
Anthropic threat intelligence uncovered a fraud network of around 28 dating apps after a prepaid account sent over 100,000 Claude API requests daily, with most chats run by autonomous AI personas and no human agent. Researchers Matthew Gore-Kormanik and Anthropic's Chris Cronbaugh documented apps including Dora, Romi, and Doni, which monetize conversations via coins; gig workers were hired only to pass liveness checks and select pregenerated replies. An operations manual written in Chinese was found inside the Doni app, and Anthropic published findings in its September 2026 AI misuse report.
A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign
A phishing campaign using fake Canada Revenue Agency tax documents has expanded to 46 countries, with 45% of activity targeting the US via RMM tools.
ANY.RUN analysis traced a campaign that began with fake Canada Revenue Agency (CRA) T4 tax documents and grew into a broader remote-access operation spanning 46 countries. The United States accounts for 45% of observed activity. Attackers impersonate trusted organizations and document types to trick victims into installing remote monitoring and management (RMM) tools.