A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject malicious JavaScript into their own browsers, in a scheme aimed at people willing to commit fraud.
ClickFix Moves into the Browser to Steal Cryptocurrency
A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject malicious JavaScript into their own browsers, in a scheme aimed at people willing to commit fraud.
Infosecurity Magazine
Publisher
Sep 9, 2026 at 1:45 PM UTC · Updated 41분 전 · 2 분 소요

Cisco Talos said in research published September 8 that the months-long campaign used the Google Visualization API to retrieve obfuscated code from a public Google Sheets document and inject it into sessions on two cryptocurrency trading sites.
The operation has survived two disruption attempts. Talos alerted Google and the targeted sites in April, and the campaign returned a week later on a new spreadsheet; as of August 11 the replacement Google documents had been reported again but remained live.
ClickFix Moves From the OS to the Browser
The campaign began in October 2025 with lures instructing targets to paste JavaScript into Chrome's navigation bar. The operators added the Visualization API in March 2026 and, from mid-April, told victims to install the Tampermonkey browser extension before adding a script.
The lures posed as leaked vulnerability reports describing non-existent API flaws at cryptocurrency swap services, promising payouts up to 38% higher. Talos said the appeal was to readers prepared to exploit a flaw they did not understand.
Article Intelligence
Topics
Regulation Signal
in progressUpdated 한 달 전
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
