Cisco Talos Exposes ClickFix Attacks Exploiting Trusted Online Services
Cisco Talos has uncovered two distinct ClickFix attack campaigns that exploit trusted online services to steal cryptocurrency, credentials, and sensitive information. The investigations reveal how attackers conceal malicious activity within familiar platforms, making it harder to detect. One campaign targeted cryptocurrency traders, using fake security reports to trick victims into pasting malicious JavaScript into their Chrome browsers. The code retrieved the main attack payload from a Google spreadsheet hidden with white text on a white background. This malware could alter cryptocurrency deposit addresses and display fake bonuses, leading to the theft of at least $10,000 from 24 Bitcoin addresses before funds were laundered through 3,000 additional addresses.
The second campaign involved fake Google verification prompts that led to credential theft, cryptocurrency theft, and remote access to compromised machines. Victims were tricked into running commands that installed the Amatera information stealer, capable of harvesting browser data, messaging applications, and private keys. The attack also disabled security software and turned infected machines into relays for attacker traffic.
Cisco Talos recommends that organizations manage browsers with the same level of control applied to laptops, monitor requests to cloud collaboration services, and reinforce employee awareness about the risks of copying and running commands. Fady Younes, Managing Director of Cybersecurity at Cisco Middle East, emphasized the need to look beyond trusted destinations and focus on which applications are making requests.
The findings were shared with Google and affected sites in April 2026, leading to the removal of the identified lures. However, the campaign resumed a week later with a new spreadsheet, remaining active into August despite repeated flagging.