Cisco Uncovers ClickFix Campaigns Exploiting Trusted Platforms for Malicious Activity
Cisco Talos, the threat intelligence arm of Cisco, has uncovered two sophisticated ClickFix campaigns that exploit trusted platforms to conceal malicious activities. These campaigns manipulate victims into running harmful code on their devices, leveraging services like Google Sheets and fake verification prompts.
The first campaign, active since October 2025, targets cryptocurrency traders with a fake security report promising a 25% bonus. Victims are tricked into pasting JavaScript into their Chrome browser or a legitimate extension, which then retrieves malicious code from a Google spreadsheet. The malware alters cryptocurrency deposit addresses, steals funds, and displays fake bonuses. Talos identified 49 Bitcoin addresses linked to the scheme, with at least 24 collecting over $10,000 before laundering the funds through 3,000 additional addresses.
The second campaign, observed in April 2026, involves fake Google CAPTCHA prompts leading to credential theft and remote access. Victims are directed to paste a command into Windows, which installs the Amatera information stealer. This malware harasses browser data, cryptocurrency wallets, and password managers, while also disabling security software and enabling remote control of compromised machines.
Fady Younes, Managing Director of Cybersecurity at Cisco Middle East, emphasized the need for organizations to strengthen controls around browsers and extensions, and to educate users about the risks of running commands from unverified sources. Cisco Talos recommends managing browsers with the same rigor as laptops and monitoring unusual activity in cloud collaboration services.