Threat actors are expanding ClickFix-style social engineering beyond simple “copy/paste this command” lures, including a campaign that abuses Pastebin comments to push victims toward executing attacker-supplied JavaScript in their browser to hijack cryptocurrency swap flows. The Pastebin comments promote a fake “Swapzone.io arbitrage exploit” and route users through a rawtext[.]host link to a Google Doc (“Swapzone.io – ChangeNOW Profit Method”) that instructs users to run JavaScript which can modify the swap process in-session and redirect funds to attacker-controlled wallets; the reporting notes this may be an early example of ClickFix being used to directly alter webpage functionality for theft.
Separately, Objective-See documented ClickFix as a rapidly growing infection technique on macOS and Windows that relies on persuading users to paste attacker-controlled commands into a terminal, enabling execution without exploiting software vulnerabilities and potentially bypassing macOS protections such as Gatekeeper and Notarization. The post describes a practical macOS-focused mitigation that intervenes at “paste time” to disrupt many ClickFix attempts, implemented in BlockBlock, while also outlining limitations and potential bypasses—reinforcing that ClickFix is primarily a user-manipulation problem that defenders should address with both technical controls and user-execution friction.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer analyzed the campaign and reported that the first-stage JavaScript loads an obfuscated second-stage payload from rawtext[.]host, which overrides Swapzone's legitimate swap-handling logic. The report described the activity as a notable ClickFix-style campaign using in-browser JavaScript to alter webpage functionality for cryptocurrency theft.
Threat actors began abusing Pastebin comments to lure cryptocurrency users with supposed Swapzone/ChangeNOW arbitrage documentation, directing them to a Google Doc that instructs victims to run malicious JavaScript in their browser. The payload injects code into Swapzone sessions to replace legitimate Bitcoin deposit addresses with attacker-controlled wallets and manipulate displayed swap details.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.