NewsLayer.com
NewsLayer PulseLIVEBTC$78,300-0.75%ETH$2,482-0.66%SOL$102.62-1.66%XRP$1.41-1.48%DOGE$0.0889-1.92%ADA$0.2155-6.01%Total Cap$2.82T+0.48%Layer Index49 Neutral

ClickFix Moves into the Browser to Steal Cryptocurrency

A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject malicious JavaScript into their own browsers, in a scheme aimed at people willing to commit fraud.

Infosecurity Magazine

Publisher

Sep 9, 2026 at 1:45 PM UTC · Updated 41분 전 · 2 분 소요

ClickFix Moves into the Browser to Steal Cryptocurrency
NewsLayer editorial artwork
번역 중…

A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject malicious JavaScript into their own browsers, in a scheme aimed at people willing to commit fraud.

Cisco Talos said in research published September 8 that the months-long campaign used the Google Visualization API to retrieve obfuscated code from a public Google Sheets document and inject it into sessions on two cryptocurrency trading sites.

The operation has survived two disruption attempts. Talos alerted Google and the targeted sites in April, and the campaign returned a week later on a new spreadsheet; as of August 11 the replacement Google documents had been reported again but remained live.

ClickFix Moves From the OS to the Browser

The campaign began in October 2025 with lures instructing targets to paste JavaScript into Chrome's navigation bar. The operators added the Visualization API in March 2026 and, from mid-April, told victims to install the Tampermonkey browser extension before adding a script.

The lures posed as leaked vulnerability reports describing non-existent API flaws at cryptocurrency swap services, promising payouts up to 38% higher. Talos said the appeal was to readers prepared to exploit a flaw they did not understand.