Tuesday, 02 January 2024 12:17 GMT

Clickfix Adopts Browser Injection To Steal Cryptocurrency Arabian Post


(MENAFN- The Arabian Post) clearfix">A ClickFix campaign is manipulating cryptocurrency users into injecting malicious JavaScript directly into their browsers, allowing attackers to replace legitimate wallet addresses and divert transfers, Cisco Talos has disclosed.

The campaign marks a shift from familiar ClickFix attacks that persuade victims to run PowerShell, Terminal or other operating-system commands. Instead, targets are instructed to paste code into Chrome's address bar or install it through the legitimate Tampermonkey browser extension, which can reload the malicious script whenever a targeted cryptocurrency site is visited.

Talos said the operation abuses Google's Visualization API to retrieve obfuscated JavaScript stored in publicly published Google Sheets. Because the requests originate from a normal browser session and travel to a trusted Google domain, the command-and-control traffic can be harder to distinguish from legitimate activity.

MENAFN09092026000152002308ID1111643108



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story