Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClickFix browser-injection crypto-fraud campaign

Campaign
First reported
Last updated
Happening score
H score 19
1 unique sources, 1 articles

Summary

Hide ▲

The ClickFix operation has shifted into browser-side JavaScript injection, expanding its fraud reach and raising the risk of cryptocurrency theft during live trading sessions. The operators used the Google Visualization API and a public Google Sheets document to deliver obfuscated code into sessions on two cryptocurrency trading sites. The activity began in October 2025, changed delivery methods in March 2026, and kept returning in repeated waves. Its lure set was aimed at people willing to exploit a perceived flaw, making the campaign a recurring crypto-skimming threat.

Related Happenings

ClickFix malicious JavaScript browser crypto-skimmer activity

Malware Activity
H score16 First: 09.09.2026 16:45 Last: 09.09.2026 16:45 Sources 1

How related: The scripts monitored page changes, replaced displayed deposit addresses and altered transaction amounts to suggest a bonus had been applied.

About this happening: A ClickFix payload now uses malicious JavaScript inside browser sessions to steal cryptocurrency deposits and copied addresses. The code is delivered through the Google...

SourTrade malvertising campaign impersonating trading and cryptocurrency brands

Campaign
H score34 First: 07.09.2026 10:53 Last: 07.09.2026 10:53 Sources 1

About this happening: The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across *...

Black Hat / Def Con attendee phishing campaign with Google Doc and DocSend lures

Campaign
H score29 First: 20.08.2026 12:30 Last: 20.08.2026 12:30 Sources 1

About this happening: A persistent phishing campaign used fake post-conference outreach and trusted file-sharing lures to target cybersecurity conference attendees, creating a path to *...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

Indirect prompt-injection web campaigns targeting AI agents

Campaign
H score37 First: 06.07.2026 18:00 Last: 06.07.2026 18:00 Sources 1

About this happening: Two real-world campaigns are using indirect prompt injection and SEO poisoning to steer AI agents into fraudulent actions and false legitimacy judgments. The lures...

Timeline

  1. 09.09.2026 16:45 2 articles · 1h ago

    ClickFix browser-injection crypto-fraud campaign

    Initial Disclosure

    In October 2025, the earliest lures instructed targets to paste JavaScript into Chrome's navigation bar. The operation then moved toward a browser-injection chain that used the Google Visualization API and later Tampermonkey.

    Show sources