ClickFix Scam Evolves: Fake Crypto 'Exploits' Trick Users into Hijacking Their Own Browsers
Researchers at Cisco Talos have identified a months-long ClickFix campaign that has evolved from tricking victims into running system commands to convincing them to inject malicious JavaScript directly into their browser. The scam uses fake 'leaked vulnerability reports' claiming flaws in cryptocurrency swap services, promising payouts up to 38% higher, to lure targets who believe they are exploiting a loophole rather than being scammed themselves.
The campaign, active since October 2025, evolved further in 2026 to use Google's Visualization API to pull hidden, obfuscated code from a public Google Sheets document, hiding it with white-on-white text formatting. Because the request comes from the victim's own browser, it blends in with normal web traffic. Some victims are also told to install the Tampermonkey browser extension, allowing the malicious script to reload every time they visit a targeted crypto trading site. Once active, the code monitors the page, swaps displayed deposit addresses, alters transaction amounts, and even replaces any cryptocurrency address the victim copies to their clipboard.
Despite two disruption attempts, including reports to Google and the affected trading sites in April, the operators simply moved to new spreadsheets and continued the campaign, with the replacement documents still live as of mid-August. Talos found the lures spreading across Telegram, cybercrime forums and text-sharing sites in regular waves.