logo

ClickFix Moves into the Browser to Steal Cryptocurrency

ID: e4ea8b04-3290-5079-a6b8-078689b0a555

STIX ID: report--e4ea8b04-3290-5079-a6b8-078689b0a555

Feed Name: Infosecurity Magazine (News)

Threat Score
65/100

Date Published: 2026-09-09

Date Updated: 2026-09-11

...
...

Cisco Talos observed a persistent ClickFix campaign that shifted from convincing users to paste commands to persuading victims to inject malicious JavaScript (via the Google Visualization API and Tampermonkey) into cryptocurrency trading sites. The scripts acted as crypto skimmers—monitoring page changes, replacing deposit addresses and amounts, overriding fetch and clipboard functions—and were linked to dozens of Bitcoin addresses with confirmed theft and evidence of mixing; the operation survived multiple takedown attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.