Cisco Talos has identified a cryptocurrency theft campaign that leverages the Google Visualization API for command and control (C2) operations. Attackers employ a "ClickFix" social engineering strategy, tricking targets—primarily those looking for "leaked" exploits—into manually injecting malicious JavaScript into their browsers or installing it via the Tampermonkey extension to ensure persistence across sessions.
The malicious scripts function as sophisticated web skimmers by hooking the browser's fetch API to intercept and modify server responses. This allows the actors to replace legitimate cryptocurrency deposit addresses with their own and display counterfeit UI elements, such as fake "bonuses," to deceive users during transactions. While currently focused on crypto-trading aggregators, these techniques highlight a broader risk of supply-chain and browser-based attacks using legitimate cloud service abuse.
Top comments (0)