INCIDENT EVIDENCE GRAPH
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.
- Victim: Browser users
- Actor: ClickFix operators
- Method: Abuse of Google Visualization API for C2, retrieval of obfuscated JavaScript from a public Google Sheets document, and injection into browser sessions