www.darkreading.com 8 Sept 2026, 17:25 UTC

ClickFix Attacks Abuse Google Services to Steal Crypto and Data

CyberSIXT Evidence Panel Source marked as original reporting

TWO recent campaigns unearthed by Cisco Talos show threat actors exploiting ClickFix-style social engineering to gain and sustain access by abusing legitimate services. In one operation, attackers aimed to steal cryptocurrency by prompting victims to paste malicious code into their browser session, then delivering a loader via a Chrome extension (TamperMonkey) and scripts hosted in Google Sheets.

Later variants used Google Sheets and Google Docs to host the payloads, with Visualisation API calls delivering malicious code. The tactic shifts the attack surface from the operating system to the browser, making the activity appear normal and harder to block with traditional network controls.

A separate campaign targeted a Ukrainian government organisation and used a competing approach (ClearFake) that exposed a phoney Google CAPTCHA prompting users to run a malicious command. That command retrieved a disguised DLL over WebDAV and launched the Amatera infostealer, capable of harvesting cryptocurrency data, credentials, and browser information, plus files. Some branches also dropped a cryptocurrency stealer and reverse proxy, and in other variants installed NetSupport Manager to provide remote access.

Cisco Talos notes the campaigns rely on legitimate services and assets—Google Chrome extensions, Google Cloud services, and public blockchain infrastructure—for command and control and persistence, enabling attackers to blend in with normal user activity. Defences proposed include tightly managed browser environments, restricted extensions, and user education emphasising that legitimate security prompts will never require pasting code into the address bar, Run dialog, or PowerShell.

View full article

Article by CyberSIXT