Cisco Talos has uncovered a cryptocurrency theft campaign that abuses Google Sheets and the Google Visualization API as a command-and-control (C2) channel.
The attackers use ClickFix-style social engineering to convince victims to execute malicious JavaScript inside their own Chrome browser sessions.
Unlike traditional ClickFix attacks, which trick users into pasting PowerShell commands into Windows Run dialogs or terminals, this operation targets the browser directly.
Victims are instructed to paste JavaScript into Chrome’s address bar or install the Tampermonkey browser extension and add a supplied script.
The campaign targets cryptocurrency users through fake vulnerability reports claiming to expose profitable flaws in crypto swap services.
The reports promise larger payouts by exploiting nonexistent API issues. Talos observed the lures on Telegram, DarkForums, Pastebin comments, and other text-sharing platforms.
ClickFix Abuses Sheets C2
The attackers use the Google Visualization API to retrieve malicious JavaScript stored in publicly published Google Sheets documents.
The API allows read-only access to spreadsheet data through URLs hosted on docs.google.com, helping the attackers blend their traffic with legitimate Google services.

The first-stage JavaScript loader queries selected spreadsheet cells, retrieves obfuscated payload fragments, combines them, and injects the resulting code into the targeted cryptocurrency website.
Earlier campaign versions asked users to paste javascript: code directly into Chrome’s navigation bar.
Later versions instructed targets to install Tampermonkey, a legitimate browser extension that allows users to run custom scripts.
Once a victim adds the malicious loader to Tampermonkey, the script runs automatically whenever they visit the targeted crypto trading site, creating persistence across sessions.
Talos found that attackers hid the payload inside spreadsheet cells using white text on a white background.
The JavaScript was heavily obfuscated using XOR encoding, hexadecimal arrays, Base64 encoding, Unicode escapes, random variable names, and junk mathematical operations.
The operators also changed XOR keys between versions to make signature-based detection harder.
The injected second-stage payload acts as a web skimmer. It modifies cryptocurrency trading interfaces and manipulates transactions before victims complete them.
The JavaScript monitors page updates using MutationObserver and replaces legitimate cryptocurrency deposit addresses with attacker-controlled Bitcoin wallet addresses.

It also overrides the browser’s fetch API to inspect server responses related to wallet and deposit functions. When the targeted website returns a legitimate deposit address, the malware replaces it before it reaches the victim.
The payload also hijacks clipboard operations. When users copy a cryptocurrency address from the trading site, the script substitutes the attacker’s wallet address in the clipboard.
Fake “bonus” interface elements and modified transaction values make victims believe they are receiving a better exchange rate or promotional reward, talosintelligence said.
Talos identified 49 Bitcoin wallet addresses linked to the campaign. Twenty-four addresses received funds, totaling 0.159 BTC, valued at roughly $10,000 in early August 2026.
The stolen funds were later moved through dozens of wallets and more than 3,000 additional addresses, likely to obscure their final destination.
Detect 58% more threats with fresh intelligence from 16K+ organizations. Integrate TI Feeds in you SOC