ClickFix Campaigns Evolve, Skim Crypto Deposits with Browsers Alone
ClickFix, a malware technique known for sidestepping download warnings and email filtering by prompting targets to run code in their browsers or operating systems, has been observed evolving in its tactics. According to Cisco Talos Threat Intelligence group, two recent campaigns have taken the technique to new heights, one of which never even touches the target's operating system.
The first campaign involves luring victims into pasting JavaScript into their Chrome address bar or installing it into the Tampermonkey browser extension, which reloads the code on every visit to the targeted site. This code skims cryptocurrency deposit addresses in server responses and the clipboard, replacing them with counterfeit 'bonus' elements.
The campaign targets swap services SwapZone.io and SimpleSwap.io, using fake leaked vulnerability reports as lures. These reports promise higher payouts or loyalty bonuses for exploiting non-existent API flaws.
Talos found 49 Bitcoin addresses in the campaign, with payments reaching 24 of them totaling $10,000 in early August. The researchers observed money moving through 30 further wallets and then into transactions involving over 3,000 addresses, consistent with a mixing operation.
The second campaign involves a compromised website where a malicious Cloudflare Worker injects ClearFake JavaScript, which is stored in a BNB Smart Chain smart contract and retrieved at page load. This technique, called EtherHiding, allows the operators to swap payloads without touching the site.