ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

ClickFix Campaign Abuses Google Sheets and Browser JavaScript to Swap Crypto Wallet Addresses on SwapZone and SimpleSwap

mediumPhishing & fraudexploited in the wildimportance 55
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Cisco Talos details a ClickFix campaign, active since October 2025, that tricks crypto traders into pasting JavaScript via Chrome's address bar or a Tampermonkey extension to hijack deposits on SwapZone and SimpleSwap; since March 2026 it fetches payloads…

Cisco Talos is tracking a months-long ClickFix campaign that shifted from OS command execution to browser-based JavaScript injection targeting sessions on two crypto swap services, SwapZone and SimpleSwap. Lures posed as leaked vulnerability reports describing non-existent API flaws, promising loyalty bonuses and payouts up to 38% higher. Victims are led to paste JavaScript into Chrome's address bar or install a Tampermonkey extension; since March 2026 the loader fetches obfuscated JavaScript from cells in public Google Sheets via the Visualization API, and a Tampermonkey variant in use since April 2026 re-injects the payload on every return visit, giving the attackers persistence despite takedown efforts. The payload behaves like a web skimmer, rewriting deposit addresses on screen and in web responses, inflating displayed amounts, hijacking the clipboard, and overriding the fetch API. Talos counted 49 attacker-controlled Bitcoin addresses, 24 of which received at least 0.159 BTC (~$10,000) by early August 2026, with proceeds routed through roughly 30 wallets and more than 3,000 addresses in apparent mixing. The campaign survived two disruption attempts; Talos urges role-based extension restrictions and browser monitoring.

  • Cisco Talos reported the campaign on September 9, 2026; it began in October 2025.
  • Targets two cryptocurrency swap services: SwapZone and SimpleSwap.
  • Lures pose as leaked vulnerability reports describing non-existent API flaws, promising loyalty bonuses and payouts up to 38% higher.
  • Victims paste JavaScript into Chrome's address bar or install a Tampermonkey extension.
  • Since March 2026, the loader fetches obfuscated JavaScript from public Google Sheets cells via the Visualization API; Tampermonkey usage observed from April 2026.
  • The payload swaps deposit addresses on screen, in web responses, and in the clipboard, inflates displayed amounts, and overrides the fetch API.
  • The Tampermonkey variant re-injects the payload on every return visit, persisting despite takedown efforts.
  • 49 attacker-controlled Bitcoin addresses tracked; 24 received at least 0.159 BTC (~$10,000) by early August 2026, and Talos believes actual losses are likely higher.

Coverage timeline

  1. · 6d ago
    Cyber Security News· 55
    Hackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks

    Cisco Talos details a crypto-theft ClickFix campaign abusing Google Sheets to swap wallet addresses, with about $10,000 in observed Bitcoin losses.

  2. · 6d ago
    Infosecurity Magazine· 48
    ClickFix Moves into the Browser to Steal Cryptocurrency

    Cisco Talos details a ClickFix campaign injecting browser JavaScript via Google Sheets to skim crypto deposits, stealing at least ~0.159 BTC since October 2025