Browser-Based 'ClickFix' Scam Uses Google Docs and Sheets to Steal Cryptocurrency
Cisco Talos has identified a months-long campaign that puts a new spin on the well-known 'ClickFix' scam. Instead of tricking victims into running malicious commands on their computer, this attack convinces users to paste code directly into their Chrome browser, either through the address bar or via a legitimate extension called Tampermonkey, which then injects malicious scripts into cryptocurrency trading websites.
What makes this campaign notable is its use of trusted Google services to hide the attack. The criminals have used the Google Visualization API, Google Sheets, and Google Docs to store and deliver their malicious scripts, making the traffic look legitimate and harder to detect or block. The lure preys on greed, promising victims a fake 'API vulnerability' that supposedly allows bigger payouts on crypto trades, targeting people active in cryptocurrency, coding, and hacking forums.
While this specific scam is aimed at individuals rather than businesses, the techniques involved, abusing trusted cloud platforms to hide malicious code and command-and-control activity, could easily be adapted for broader attacks, including supply-chain compromises of e-commerce and customer-facing systems. Talos notes this is part of a wider pattern of attackers, including state-sponsored groups, hiding behind legitimate Google infrastructure to avoid detection.