Cryptocurrency Stealers Use Google-Hosted C2 to Inject Malicious Code
Cisco Talos has tracked a cryptocurrency-stealing campaign that uses Google-hosted command and control (C2) to inject malicious JavaScript into victims' browsers. The actors behind this campaign abuse the Google Visualization API, which provides unauthenticated read-only access to publicly published Google Sheets spreadsheets. They use social engineering tactics, similar to 'ClickFix', where targets are convinced to paste JavaScript code into their browser's navigation bar or install it through a legitimate Chrome plugin called Tampermonkey.
The campaign began in early October 2025 and has targeted individuals frequenting web discussion boards and forums focused on cryptocurrency trading, software development, and hacking. The lure used is designed to appeal to would-be cybercriminals who are looking to exploit a nonexistent API vulnerability for financial gain.
Talos observed the actors using multiple lures, including email, comments on Pastebin and text-sharing sites, and direct messages in forums like Telegram. They also set up a Telegram channel to facilitate the scam, posting links to versions of the lure document in dark web forums and text-sharing sites.