Crypto Scammers Abuse Google API for Browser-Based Heists
Cisco Talos has tracked a cryptocurrency-stealing campaign that exploits Google's Visualization API for command and control (C2). The attackers use a variation on ClickFix social engineering to convince victims to inject malicious code into their browser sessions.
The lures used in the campaign pose as leaked vulnerability reports describing non-existent API flaws at cryptocurrency swap services. They are distributed through Telegram, DarkForums, and paste sites, targeting users willing to exploit these flaws for financial gain.
The injected script functions as a web skimmer, hooking the browser's fetch API and replacing cryptocurrency deposit addresses in server responses and user clipboards. It also displays counterfeit 'bonus' interface elements.