ClickFix malicious JavaScript browser crypto-skimmer activity
Malware Activity
Summary
Hide ▲
Show ▼
A ClickFix payload now uses malicious JavaScript inside browser sessions to steal cryptocurrency deposits and copied addresses. The code is delivered through the Google Visualization API and a public Google Sheets document, then injected into sessions on two cryptocurrency trading sites. It replaces deposit addresses, alters transaction amounts, and can override browser fetch behavior to divert funds. The browser-based design and repeated reloading make the skimming harder to spot and increase theft risk.
Related Happenings
ClickFix browser-injection crypto-fraud campaign
Campaign
H score19
First: 09.09.2026 16:45
Last: 09.09.2026 16:45
Sources 1
How related:
Talos found the material on Telegram, the cybercrime forum DarkForums and text-sharing sites, with waves of messages sent at least twice a month.
About this happening:
The ClickFix operation has shifted into browser-side JavaScript injection, expanding its fraud reach and raising the risk of cryptocurrency theft during live trading s...
ClickFix browser-injection crypto-fraud campaign
CampaignHow related: Talos found the material on Telegram, the cybercrime forum DarkForums and text-sharing sites, with waves of messages sent at least twice a month.
About this happening: The ClickFix operation has shifted into browser-side JavaScript injection, expanding its fraud reach and raising the risk of cryptocurrency theft during live trading s...
JSCeal malware activity
Malware Activity
H score29
First: 07.09.2026 10:53
Last: 07.09.2026 10:53
Sources 1
About this happening:
JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...
JSCeal malware activity
Malware ActivityAbout this happening: JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...
ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
H score22
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
ClickFix AmnesiaStealer distribution campaign targeting mac users
CampaignAbout this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
Latest development: 16.08.2026 18:07
Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
Google DoubleClick malspam campaign delivering DesckVB RAT
Campaign
H score33
First: 03.06.2026 19:29
Last: 03.06.2026 19:29
Sources 1
About this happening:
A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
Google DoubleClick malspam campaign delivering DesckVB RAT
CampaignAbout this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware Activity
H score29
First: 01.04.2026 16:30
Last: 01.04.2026 16:30
Sources 1
About this happening:
The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware ActivityAbout this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Timeline
-
09.09.2026 16:45 2 articles · 1h ago
ClickFix shifts into browser-based crypto skimming
Initial DisclosureCisco Talos found that the ClickFix campaign shifted from lures that made victims paste JavaScript into Chrome's navigation bar to malicious JavaScript injected into browser sessions on two cryptocurrency trading sites. The operators used the Google Visualization API to retrieve obfuscated code from a public Google Sheets document, then changed tactics in March 2026 by adding the API and from mid-April by telling victims to install the Tampermonkey browser extension before adding a script. Talos said the lures posed as leaked vulnerability reports about non-existent API flaws at cryptocurrency swap services and that the scripts replaced deposit addresses, altered transaction amounts, overrode fetch responses, and swapped clipboard data; the group also survived disruption attempts after Talos alerted Google and the targeted sites in April, with replacement Google documents still live on August 11. Talos identified 49 Bitcoin addresses across the campaign, and one decoded set of wallets covering April to late June received victim funds totaling 0.159 BTC, about $10,000 at early August valuations.
Show sources
- ClickFix Moves into the Browser to Steal Cryptocurrency — www.infosecurity-magazine.com — 09.09.2026 16:45
- ClickFix Moves into the Browser to Steal Cryptocurrency — www.infosecurity-magazine.com — 09.09.2026 16:45