ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Executive Summary
Cisco Talos reports a cryptocurrency‑stealing campaign that uses the Google Visualization API as a command‑and‑control channel. The attackers host obfuscated JavaScript in a publicly accessible Google Sheets document, which is fetched and injected into victims’ browser sessions, enabling the theft of crypto assets.
Intelligence Metadata - Source Publisher: Cisco Talos - Published Date: 2026-09-08T10:00:38+00:00 - Category: campaigns
Original Description: Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.
"It is only with the heart that one can see rightly, what is essential is invisible to the eye."
— Antoine de Saint-Exupery