Clickfix Adopts Browser Injection To Steal Cryptocurrency Arabian Post
The campaign marks a shift from familiar ClickFix attacks that persuade victims to run PowerShell, Terminal or other operating-system commands. Instead, targets are instructed to paste code into Chrome's address bar or install it through the legitimate Tampermonkey browser extension, which can reload the malicious script whenever a targeted cryptocurrency site is visited.
Talos said the operation abuses Google's Visualization API to retrieve obfuscated JavaScript stored in publicly published Google Sheets. Because the requests originate from a normal browser session and travel to a trusted Google domain, the command-and-control traffic can be harder to distinguish from legitimate activity.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment