ClickFix Uses Google Sheets to Hijack Crypto Wallets
Key Takeaways A new ClickFix campaign leverages Google Sheets and the Google Visualization API to hijack cryptocurrency transactions. Attackers use fake “API flaw” or “loyalty...
Key Takeaways
- A new ClickFix campaign leverages Google Sheets and the Google Visualization API to hijack cryptocurrency transactions.
- Attackers use fake “API flaw” or “loyalty bonus” lures on forums and messaging apps to trick users into executing malicious JavaScript in their browsers.
- The malicious script functions as a web skimmer, altering displayed wallet addresses, intercepting transaction data, and replacing clipboard contents with attacker-controlled addresses.
- The campaign has already siphoned approximately 0.159 BTC, valued at around $10,000 as of August 2026, though total losses may be higher.
- This browser-based attack method can achieve persistence through browser extensions, making simple takedowns ineffective.
Hackers Exploit Google Sheets in Sophisticated Crypto Wallet Hijack
Cybercriminals are employing an innovative and stealthy tactic in a new cryptocurrency theft campaign, utilizing Google Sheets as a command-and-control channel. This operation, dubbed “ClickFix,” transforms a user’s web browser into an execution environment for malicious code, diverging from traditional malware that relies on installing programs directly onto a victim’s system. This browser-centric approach allows attackers to bypass many conventional endpoint security measures.
Table Of Content
The attackers initiate the scheme by disseminating deceptive reports that falsely claim to reveal lucrative flaws within popular cryptocurrency swap services. Victims are enticed to manually inject JavaScript code into their Chrome browser’s address bar or integrate it into a browser extension. This seemingly innocuous action grants the malicious code the ability to execute within the context of legitimate cryptocurrency trading platforms the user visits.
Evolution of the ClickFix Campaign
The ClickFix campaign first emerged with its characteristic lures in October 2025. By March 2026, the attackers had refined their methodology to incorporate Google’s Visualization API, a move that significantly enhanced their operational stealth and resilience. Researchers have identified promotional messages for this scheme across various platforms, including Telegram, DarkForums, email, and paste sites. These messages specifically target individuals with interests in cryptocurrency trading, programming, hacking, and rapid financial gains, promising inflated returns.
The ultimate goal of this elaborate deception is to execute a wallet-address swap at the critical moment a user intends to initiate a cryptocurrency deposit. This manipulation ensures that funds are rerouted directly to the attacker’s wallet instead of the intended recipient.
According to a report by Cisco Talos, shared with Cyber Security News (CSN), investigators have identified 49 Bitcoin addresses associated with this operation. Of these, 24 addresses collectively received approximately 0.159 BTC, which was valued at around $10,000 in early August 2026. Cisco Talos noted that the actual total amount stolen could be considerably higher.
Hackers Abuse Google Sheets
This iteration of the ClickFix campaign represents a significant shift from previous tactics. Rather than instructing users to open a terminal or execute a program, the lures now guide victims to modify their browser environment. This allows subsequent attack stages to masquerade as legitimate traffic interacting with trusted Google services, thereby evading suspicion.
Early lures in the campaign promoted a fabricated API flaw, promising users approximately 38 percent higher payouts on the SwapZone platform. A more recent variant claimed a SimpleSwap loyalty feature could provide a 25 percent bonus. To exploit these purported features, victims were instructed to install the Tampermonkey browser extension and then paste a malicious loader script.
This evolution aligns with recent ClickFix delivery campaigns, which increasingly depend on the victim performing the dangerous actions themselves. In this particular scheme, the loader script retrieves hidden and obfuscated JavaScript from specific cells within a publicly accessible Google Sheet, leveraging the Google Visualization API. It then reconstructs this code and injects it directly into the active web page.
The injected malicious code operates as a sophisticated web skimmer. It actively monitors the transaction pages on cryptocurrency trading sites, dynamically altering the displayed deposit addresses to those controlled by the attackers. Furthermore, it intercepts web responses containing wallet information and replaces any copied wallet addresses in the user’s clipboard with the attacker’s alternative. To further entice victims, the script also injects false bonus information, making the fraudulent transaction appear more appealing.
The use of browser extensions provides the attackers with a crucial advantage: persistence. Once installed, the malicious loader can reconstruct and reinject its payload every time the victim revisits the targeted cryptocurrency trading site. The operators behind this campaign have also demonstrated adaptability, frequently altering their Google Sheet and hosting infrastructure in response to takedown attempts, rendering simple disruption efforts short-lived.
The implications of this attack extend beyond cryptocurrency theft. Similar browser-side manipulation techniques could be applied to compromise other online forms or customer-facing applications. The abuse of legitimate and widely trusted online services, such as Google Sheets, mirrors trusted mirror ClickFix abuse, where attackers leverage credible platforms to reduce suspicion.
What You Should Do
- Be Skeptical of “Bonus” Claims: Treat any online claim of secret trading bonuses, exploits, or special API access as a high-risk warning sign. Legitimate platforms will not require unconventional methods for enhanced features.
- Never Paste Code: Absolutely avoid pasting code into your browser’s address bar, developer console, terminal, or browser extensions, especially if prompted by an external source. This is a critical vector for malicious code injection.
- Verify Wallet Addresses Manually: Before confirming any cryptocurrency transaction, meticulously compare the wallet address displayed on your screen with the address copied to your clipboard. Consider verifying the address through an independent, trusted channel.
- Manage Browser Extensions: Organizations should implement strict policies for browser extension usage, limiting installations to approved, essential extensions and restricting developer-level browser functions for most users.
- Monitor for Unusual Google Docs Activity: Security teams should monitor network traffic for unusual requests to Google Docs or Sheets from browser sessions that do not correspond to normal document interaction, particularly after employees access untrusted websites or links.
- Audit Third-Party Code: Web application owners must regularly audit and test all third-party code integrated into their platforms. Immediately remove any unexplained or heavily obfuscated JavaScript.
- Enhance Security Training: Conduct comprehensive security awareness training that emphasizes behavioral risks beyond just blocking malicious domains. Educate employees and customers that copying and executing code from external documents, messages, or suspicious “research” pages can lead to full browser session compromise, even on seemingly legitimate services.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | docs.google[.]com |
Google-hosted documents and Sheets were used for lure hosting and payload retrieval through the Visualization API |
| Domain | paste[.]sh |
Hosted first-stage JavaScript loader scripts used in the campaign |
| URL | https[:]//paste[.]sh/dQfdExjo#AqjB4BBt]lwLt2NKrlC0x8J9O |
Paste site URL promoted for the Tampermonkey-based loader script |
| Domain | SwapZone[.]io |
Cryptocurrency trading site targeted by the initial lure version |
| Domain | SimpleSwap[.]io |
Cryptocurrency trading site targeted by the later Tampermonkey-based lure |
| File name | API Logic Flaw |
Name used for the fraudulent Google Docs lure document |
| Tool or service | Obfuscator[.]io |
JavaScript obfuscation service whose output patterns were observed in payload samples |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.