Cisco Talos: ClickFix Campaign Uses Google Sheets as C2 to Skim Crypto Deposits from Browsers
Cisco Talos details a ClickFix crypto-theft campaign, running since October 2025, that abuses Google Sheets and the Visualization API as C2 to swap deposit addresses on SimpleSwap and SwapZone, netting ~0.159 BTC (~$10,000) across 24 of 49 tracked Bitcoin…
Cisco Talos reports a months-long ClickFix-style cryptocurrency theft campaign that began in October 2025 and shifted from OS command execution to injecting obfuscated JavaScript directly into victims' Chrome browser sessions. Lures, spread via Telegram, DarkForums, and Pastebin, pose as leaked 'API Logic Flaw' vulnerability reports promising bonuses of 25-38% on SimpleSwap and SwapZone swaps. Victims are tricked into pasting the JavaScript into Chrome's address bar or, from April 2026, into the legitimate Tampermonkey extension, whose user script re-injects the payload on every return visit for persistence without OS-level compromise. Since March 2026 the loader has fetched payloads from cells in public Google Sheets via the Google Visualization API, hiding C2 traffic inside trusted HTTPS. The payload acts as a browser-based web skimmer, replacing deposit addresses and amounts on screen, in web responses, and in the clipboard, while overriding the fetch API. Talos tracked 49 attacker-controlled Bitcoin addresses, with 24 receiving at least 0.159 BTC (~$10,000) by early August 2026; proceeds were routed through roughly 30 wallets and more than 3,000 addresses in apparent mixing. The campaign survived two disruption attempts, and Talos recommends role-based extension restrictions and browser monitoring.
- Attribution/disclosure: Cisco Talos, reported September 9, 2026
- Campaign timeline: began October 2025; Google Visualization API delivery added March 2026; Tampermonkey variant from April 2026
- Targets: cryptocurrency traders on SimpleSwap and SwapZone
- Lures: fake 'API Logic Flaw' vulnerability reports promising bonuses of 25-38%, spread via Telegram, DarkForums, and Pastebin
- Delivery: victims paste obfuscated JavaScript into Chrome's address bar or the Tampermonkey extension; loader fetches payloads from public Google Sheets cells via the Google Visualization API
- C2: Google Sheets and Visualization API hidden in trusted HTTPS traffic
- Impact: web skimmer swaps deposit addresses, inflates displayed amounts, hijacks the clipboard, and overrides the fetch API
- Persistence: Tampermonkey user script re-injects payload on return visits without OS-level compromise
Coverage timelineoldest first · each row is one article
- · 7d agoHackers Abuse Google Sheets as C2 in ClickFix Attacks to Steal Cryptocurrency
GBHackers· 52
Cisco Talos tracks a ClickFix crypto-theft campaign using Google Sheets as C2 to swap deposit addresses in Chrome.