ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos Intelligence Version 1 original current

Imported from official source

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.

This version

Version
1 of 1
Recorded
September 18, 2026 11:34
Change
Initial
Content hash
f3d9bffb62af2f796ea97311f3c7d6d6
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.