Criminals Hide Crypto Theft Operation in Public Google Spreadsheet
Cisco's Talos threat intelligence organization has discovered a worrying trend in crypto theft operations. Attackers are using publicly trusted services, such as Google Docs and blockchain, to host malicious code. This makes it difficult to spot the attacks, as they appear as legitimate requests to trusted services.
The first campaign, which began in October 2025, targets cryptocurrency traders with a fake leaked security report claiming a flaw at two currency swap sites. The report promises a 25% bonus, but the real code lives in a publicly published Google spreadsheet. The operators even hid it in the sheet as white text on a white background.
The victims are tricked into pasting JavaScript into the Chrome address bar or adding it to a legitimate browser add-on. The pasted snippet is only a fetcher, and the real code rewrites the deposit address shown on the trading page, replacing any address the victim copies. The attackers launder the funds through more than 3,000 further addresses.
The second case began in April 2026 with unusual activity at a Ukrainian government organization. Talos assesses with moderate confidence that this was part of a broad crypto and credential theft operation. The pattern repeats, with different cover, but the methods are the same.
Cisco's Field CTO Security, Jan Heijdra, recommends managing the browser like you manage the laptop, controlling which extensions staff can install. He also advises watching for requests to cloud collaboration services from applications or browser sessions that have no reason to make them.