Pastebin ClickFix JavaScript crypto swap hijacking campaign
Campaign
Summary
Hide ▲
Show ▼
The Pastebin-driven ClickFix-style campaign is tricking cryptocurrency users into running malicious JavaScript in their browser and hijacking Bitcoin swap transactions. The lure poses as a Swapzone.io arbitrage exploit, but the code changes the swap process inside the victim session. The activity appears widespread, with recurring comments and pages showing 1 to 5 active viewers. The result is direct theft to attacker-controlled Bitcoin wallets and little practical recovery after the transfer.
Related Happenings
UNC1069 GhostCall cryptocurrency social-engineering campaign
Campaign
H score37
First: 11.02.2026 08:50
Last: 11.02.2026 08:50
Sources 1
About this happening:
UNC1069 is actively targeting the cryptocurrency sector with a social-engineering campaign designed to steal credentials and data for financial theft. The operatio...
UNC1069 GhostCall cryptocurrency social-engineering campaign
CampaignAbout this happening: UNC1069 is actively targeting the cryptocurrency sector with a social-engineering campaign designed to steal credentials and data for financial theft. The operatio...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
Campaign
H score33
First: 11.02.2026 00:17
Last: 11.02.2026 00:17
Sources 1
About this happening:
Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
CampaignAbout this happening: Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...
UNC1069 seven-family macOS malware deployment
Malware Activity
H score30
First: 11.02.2026 00:17
Last: 11.02.2026 00:17
Sources 1
About this happening:
UNC1069 first targeted a cryptocurrency-sector fintech with a Telegram-to-Calendly-to-spoofed Zoom ClickFix chain that used AI-generated video, AppleScript, and a maliciou...
UNC1069 seven-family macOS malware deployment
Malware ActivityAbout this happening: UNC1069 first targeted a cryptocurrency-sector fintech with a Telegram-to-Calendly-to-spoofed Zoom ClickFix chain that used AI-generated video, AppleScript, and a maliciou...
Bizarre Bazaar campaign targeting exposed LLM and MCP endpoints
Campaign
H score80
First: 28.01.2026 15:15
Last: 28.01.2026 15:15
Sources 1
About this happening:
Bizarre Bazaar is an active LLMjacking campaign targeting exposed LLM and MCP endpoints to monetize unauthorized access to AI infrastructure. Researchers say the opera...
Bizarre Bazaar campaign targeting exposed LLM and MCP endpoints
CampaignAbout this happening: Bizarre Bazaar is an active LLMjacking campaign targeting exposed LLM and MCP endpoints to monetize unauthorized access to AI infrastructure. Researchers say the opera...
Latest development: 29.01.2026 20:37
Researchers said Operation Bizarre Bazaar, an LLMjacking marketplace that scans for exposed Ollama, vLLM, and OpenAI-compatible APIs without authentication and resells access through silver[.]inc, has been traced to Hecker (aka Sakuya and LiveGamer101).
YouTubeTA StealC malware campaign against cracked-Adobe seekers in 2025
Campaign
H score76
First: 16.01.2026 23:00
Last: 16.01.2026 23:00
Sources 1
About this happening:
The YouTubeTA operation ran malware campaigns throughout 2025, turning cracked Adobe Photoshop and Adobe After Effects searches into a large-scale credential theft...
YouTubeTA StealC malware campaign against cracked-Adobe seekers in 2025
CampaignAbout this happening: The YouTubeTA operation ran malware campaigns throughout 2025, turning cracked Adobe Photoshop and Adobe After Effects searches into a large-scale credential theft...
Timeline
-
15.02.2026 17:17 2 articles · 5mo ago
Pastebin ClickFix crypto swap hijacking campaign
Initial DisclosureThreat actors used Pastebin comments and a Google Docs lure to promote a fake Swapzone.io arbitrage method that instructed cryptocurrency users to paste and execute JavaScript in the browser address bar. The malicious code loaded a secondary payload from https://rawtext[.]host/raw?btulo3, overrode the legitimate Next.js swap interface on Swapzone.io, replaced the deposit address with attacker-controlled Bitcoin wallets, and altered displayed rates and offer values to make the swap appear profitable.
Show sources
- Pastebin comments push ClickFix JavaScript attack to hijack crypto swaps — www.bleepingcomputer.com — 15.02.2026 17:17
- Pastebin comments push ClickFix JavaScript attack to hijack crypto swaps — www.bleepingcomputer.com — 15.02.2026 17:17