Cryptocurrency Thieves Hide in Plain Sight with Public Google Spreadsheets
Cisco's threat intelligence organization, Talos, has uncovered two campaigns of cryptocurrency theft operations that are hiding in plain sight. The attackers use trusted services such as Google Docs and blockchain to host their malicious code.
The first campaign, which began in October 2025, targets cryptocurrency traders with a fake leaked security report claiming a flaw at two currency swap sites. Victims are tricked into pasting JavaScript into the Chrome address bar or adding it to a legitimate browser add-on, which fetches the real code from a publicly published Google spreadsheet.
The attackers use a skimmer to rewrite the deposit address shown on the trading page and replace any address copied by the victim. Talos traced 49 Bitcoin addresses, of which 24 collected victim funds worth at least roughly $10,000, and laundered them through more than 3,000 further addresses.
The second case began in April 2026 with unusual activity at a Ukrainian government organization. The attackers used malicious code planted on a compromised website to pull its next instructions from a public blockchain. Victims are tricked into pasting a command into Windows, which installs a stealer known as Amatera.
Talos assesses with moderate confidence that the second case was part of a broad crypto and credential theft operation rather than an attack on the Ukrainian organization specifically.