ClickFix browser-injection crypto-fraud campaign
Campaign
Summary
Hide ▲
Show ▼
The ClickFix operation has shifted into browser-side JavaScript injection, expanding its fraud reach and raising the risk of cryptocurrency theft during live trading sessions. The operators used the Google Visualization API and a public Google Sheets document to deliver obfuscated code into sessions on two cryptocurrency trading sites. The activity began in October 2025, changed delivery methods in March 2026, and kept returning in repeated waves. Its lure set was aimed at people willing to exploit a perceived flaw, making the campaign a recurring crypto-skimming threat.
Related Happenings
ClickFix malicious JavaScript browser crypto-skimmer activity
Malware Activity
H score16
First: 09.09.2026 16:45
Last: 09.09.2026 16:45
Sources 1
How related:
The scripts monitored page changes, replaced displayed deposit addresses and altered transaction amounts to suggest a bonus had been applied.
About this happening:
A ClickFix payload now uses malicious JavaScript inside browser sessions to steal cryptocurrency deposits and copied addresses. The code is delivered through the Google...
ClickFix malicious JavaScript browser crypto-skimmer activity
Malware ActivityHow related: The scripts monitored page changes, replaced displayed deposit addresses and altered transaction amounts to suggest a bonus had been applied.
About this happening: A ClickFix payload now uses malicious JavaScript inside browser sessions to steal cryptocurrency deposits and copied addresses. The code is delivered through the Google...
SourTrade malvertising campaign impersonating trading and cryptocurrency brands
Campaign
H score34
First: 07.09.2026 10:53
Last: 07.09.2026 10:53
Sources 1
About this happening:
The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across *...
SourTrade malvertising campaign impersonating trading and cryptocurrency brands
CampaignAbout this happening: The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across *...
Black Hat / Def Con attendee phishing campaign with Google Doc and DocSend lures
Campaign
H score29
First: 20.08.2026 12:30
Last: 20.08.2026 12:30
Sources 1
About this happening:
A persistent phishing campaign used fake post-conference outreach and trusted file-sharing lures to target cybersecurity conference attendees, creating a path to *...
Black Hat / Def Con attendee phishing campaign with Google Doc and DocSend lures
CampaignAbout this happening: A persistent phishing campaign used fake post-conference outreach and trusted file-sharing lures to target cybersecurity conference attendees, creating a path to *...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Indirect prompt-injection web campaigns targeting AI agents
Campaign
H score37
First: 06.07.2026 18:00
Last: 06.07.2026 18:00
Sources 1
About this happening:
Two real-world campaigns are using indirect prompt injection and SEO poisoning to steer AI agents into fraudulent actions and false legitimacy judgments. The lures...
Indirect prompt-injection web campaigns targeting AI agents
CampaignAbout this happening: Two real-world campaigns are using indirect prompt injection and SEO poisoning to steer AI agents into fraudulent actions and false legitimacy judgments. The lures...
Timeline
-
09.09.2026 16:45 2 articles · 1h ago
ClickFix browser-injection crypto-fraud campaign
Initial DisclosureIn October 2025, the earliest lures instructed targets to paste JavaScript into Chrome's navigation bar. The operation then moved toward a browser-injection chain that used the Google Visualization API and later Tampermonkey.
Show sources
- ClickFix Moves into the Browser to Steal Cryptocurrency — www.infosecurity-magazine.com — 09.09.2026 16:45
- ClickFix Moves into the Browser to Steal Cryptocurrency — www.infosecurity-magazine.com — 09.09.2026 16:45