ClickFix Campaign Injects Malicious JavaScript into Google Sheets
A sophisticated cyberattack campaign, dubbed ClickFix, targeted cryptocurrency users by manipulating browser code execution and injecting malicious JavaScript into Google Sheets. The attackers created a fake vulnerability report in Google Docs, which they shared on Telegram, DarkForums, and paste sites.
The lure claimed that an outdated API function at a cryptocurrency swap service could yield a larger payout or loyalty bonus. Targets were instructed to copy code from a paste site and paste it into Chrome's address bar with a javascript: prefix, or install the legitimate Tampermonkey extension and add a supplied userscript.
Once installed, the second-stage payload retrieved obfuscated JavaScript fragments from publicly published Google Sheets, reconstructed the payload, and injected it into the active browser session. The script altered responses, pages, and copied addresses to support the lure's story and made unauthorized changes appear as part of a special exchange feature.