A recent ClickFix campaign has taken a new approach, moving from tricking users into running commands on their computers to convincing them to inject malicious JavaScript into their own browsers. This scheme targets individuals willing to engage in fraudulent activities.
According to research by Cisco Talos published on September 8, the campaign has been ongoing for several months. It utilizes the Google Visualization API to retrieve obfuscated code from a public Google Sheets document and inject it into sessions on two cryptocurrency trading sites.
Despite two attempts to disrupt the operation, it has persisted. Talos initially alerted Google and the targeted sites in April, prompting the campaign to resurface a week later using a new spreadsheet. As of August 11, replacement Google documents have been reported but remain active.
The ClickFix campaign originated in October 2025 with instructions for targets to paste JavaScript into Chrome’s navigation bar. In March 2026, the operators incorporated the Visualization API and later instructed victims to install the Tampermonkey browser extension before adding a script.
The lures used in the campaign falsely described non-existent API vulnerabilities at cryptocurrency swap services, promising inflated payouts to individuals willing to exploit these flaws. The malicious content was distributed via Telegram, DarkForums, and text-sharing platforms, with messages sent out at least bi-monthly.
By utilizing the Visualization API, the attackers were able to gain read-only access to Google Sheets documents published online. The payload cells were concealed by formatting the text in white to blend in with the background.
The injected scripts functioned as crypto skimmers, monitoring page changes, altering displayed deposit addresses, and manipulating transaction amounts to indicate a bonus had been applied. Additionally, the scripts intercepted deposit responses and replaced attacker wallet addresses before the information reached the victim.
A total of 49 Bitcoin addresses were identified across the campaign, with funds totaling 0.159 BTC (approximately $10,000) being transferred to 24 of the addresses between April and late June. The researchers suspect that the actual amount may be higher, as the proceeds were routed through multiple wallets and addresses in what appeared to be a mixing operation.
While the ClickFix campaign may not pose a direct threat to most organizations, the techniques employed highlight the importance of restricting browser extensions based on their role and monitoring browser sessions for requests to Google Docs. Stay informed about cybersecurity threats and take proactive measures to protect your online assets.
