ClickFix Campaign Abuses Google Sheets C2 to Inject Malicious JavaScript Into Chrome

Cisco Talos has uncovered a cryptocurrency theft campaign that abuses Google Sheets and the Google Visualization API as a command-and-control (C2) channel.

The attackers use ClickFix-style social engineering to convince victims to execute malicious JavaScript inside their own Chrome browser sessions.

Unlike traditional ClickFix attacks, which trick users into pasting PowerShell commands into Windows Run dialogs or terminals, this operation targets the browser directly.

Victims are instructed to paste JavaScript into Chrome’s address bar or install the Tampermonkey browser extension and add a supplied script.

The campaign targets cryptocurrency users through fake vulnerability reports claiming to expose profitable flaws in crypto swap services.

The reports promise larger payouts by exploiting nonexistent API issues. Talos observed the lures on Telegram, DarkForums, Pastebin comments, and other text-sharing platforms.

ClickFix Abuses Sheets C2

The attackers use the Google Visualization API to retrieve malicious JavaScript stored in publicly published Google Sheets documents.

The API allows read-only access to spreadsheet data through URLs hosted on docs.google.com, helping the attackers blend their traffic with legitimate Google services.

Telegram channel post promoting the “API Exploit” lure document (Source: talosintelligence)
Telegram channel post promoting the “API Exploit” lure document (Source: talosintelligence)

The first-stage JavaScript loader queries selected spreadsheet cells, retrieves obfuscated payload fragments, combines them, and injects the resulting code into the targeted cryptocurrency website.

Earlier campaign versions asked users to paste javascript: code directly into Chrome’s navigation bar.

Later versions instructed targets to install Tampermonkey, a legitimate browser extension that allows users to run custom scripts.

Once a victim adds the malicious loader to Tampermonkey, the script runs automatically whenever they visit the targeted crypto trading site, creating persistence across sessions.

Talos found that attackers hid the payload inside spreadsheet cells using white text on a white background.

The JavaScript was heavily obfuscated using XOR encoding, hexadecimal arrays, Base64 encoding, Unicode escapes, random variable names, and junk mathematical operations.

The operators also changed XOR keys between versions to make signature-based detection harder.

The injected second-stage payload acts as a web skimmer. It modifies cryptocurrency trading interfaces and manipulates transactions before victims complete them.

The JavaScript monitors page updates using MutationObserver and replaces legitimate cryptocurrency deposit addresses with attacker-controlled Bitcoin wallet addresses.

A screenshot of a private message on a dark web forum linking to the Telegram channel operated by the scammers (Source: talosintelligence)
A screenshot of a private message on a dark web forum linking to the Telegram channel operated by the scammers (Source: talosintelligence)

It also overrides the browser’s fetch API to inspect server responses related to wallet and deposit functions. When the targeted website returns a legitimate deposit address, the malware replaces it before it reaches the victim.

The payload also hijacks clipboard operations. When users copy a cryptocurrency address from the trading site, the script substitutes the attacker’s wallet address in the clipboard.

Fake “bonus” interface elements and modified transaction values make victims believe they are receiving a better exchange rate or promotional reward, talosintelligence said.

Talos identified 49 Bitcoin wallet addresses linked to the campaign. Twenty-four addresses received funds, totaling 0.159 BTC, valued at roughly $10,000 in early August 2026.

The stolen funds were later moved through dozens of wallets and more than 3,000 additional addresses, likely to obscure their final destination.

Detect 58% more threats with fresh intelligence from 16K+ organizations. Integrate TI Feeds in you SOC

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories