Cryptocurrency Stealers Abuse Google Sheets to Deliver Malicious Code
A recent cryptocurrency-stealing campaign uses Google Sheets as a covert command-and-control channel to deliver obfuscated JavaScript directly into victims' browser sessions. The operation, identified as ClickFix, marks a significant evolution of social engineering tactics.
The attackers manipulate users into running malicious code inside Chrome by disguising it as an opportunity to exploit a supposed vulnerability in cryptocurrency swap platforms. Victims are instructed to copy and paste a JavaScript snippet into the browser address bar or install a legitimate Tampermonkey extension with a supplied user script.
The campaign targets individuals active in cryptocurrency, software development, cybersecurity, and hacking communities who may be tempted by the promise of inflated returns. Cisco Talos researchers observed lures spreading through Telegram channels, DarkForums private messages, and Pastebin comments.