Cisco Talos identified a months-long ClickFix cryptocurrency-theft campaign that tricks users into injecting malicious JavaScript into Chrome or installing it through Tampermonkey. Lures impersonate leaked reports of cryptocurrency-exchange API flaws and promise SwapZone or SimpleSwap trading bonuses. The scripts use Google Sheets and the Google Visualization API for command-and-control, hiding second-stage retrieval within trusted docs.google.com traffic, then replace cryptocurrency deposit addresses in webpages, intercepted responses, and the clipboard. Talos linked 49 Bitcoin wallets to the operation; 24 active wallets received 0.159 BTC, roughly $10,000 in early August 2026.
ClickFix techniques continue to enable broader malware delivery as well as browser-based theft. A blocked July 2026 intrusion used phishing to induce in-memory PowerShell execution, followed by a loader, process injection into svchost.exe or explorer.exe, and deployment of PureLogs Stealer targeting browser credentials, cookies, banking data, and cryptocurrency wallets. Earlier activity tracked by Proofpoint showed ClearFake and TA571 using fake browser or certificate warnings and malicious clipboard content to persuade victims to manually run PowerShell, delivering stealers, RATs, loaders, and cryptominers. Organizations should treat unexpected browser verification prompts and copy-paste instructions as high-risk, while monitoring for browser script injection, anomalous Google-hosted script retrieval, and credential or wallet-address manipulation.

Pull IOCs and campaign context straight into your stack.
16 events from the most recent confirmed update back to the earliest known activity.
CERT ITrust published a technical analysis of the blocked PureLogs Stealer intrusion attempt, identifying infrastructure at 158.94.211.92, the associated loaders, anti-analysis techniques, and malware sample indicators. The report cautioned that extracted IOCs required independent validation before operational blocking.
The cryptocurrency-stealing ClickFix campaign remained active through at least August 11, 2026. Researchers identified 49 Bitcoin addresses; 24 recipient wallets received 0.159 BTC, valued at about $10,000 in early August, before proceeds were routed through additional wallets and thousands of addresses.
After posts on shared text sites were disrupted, the cryptocurrency-stealing actors moved all campaign components to Google Docs and Google Sheets. The operation concealed payload text as white-on-white spreadsheet cells and continued using Google-hosted delivery infrastructure.
An EDR alert at an ITrust client blocked network communication from a memory-resident PowerShell command executed after a ClickFix phishing lure. The multistage chain downloaded hybrid PE/shellcode loaders, injected into svchost.exe or explorer.exe, and targeted browser credentials, cookies, banking data, and cryptocurrency wallets with PureLogs Stealer.
A revised lure targeted SimpleSwap users, falsely asserting that a loyalty-bonus flaw could increase trade value by 25%. Later variants instructed targets to install Tampermonkey and add a malicious loader, providing persistence when they visited SimpleSwap.
The first observed Google Docs lure targeted SwapZone users and was active from April 12 through April 16. It falsely claimed an older ChangeNOW API weakness could yield approximately 38% higher cryptocurrency-trade payouts.
Cisco Talos shared information about the cryptocurrency-stealing campaign with Google and the targeted cryptocurrency sites. The actors resumed operations about a week later using a new Google Sheet and a paste.sh script.
The cryptocurrency-stealing actors began delivering malicious scripts stored in publicly published Google Sheets through the Google Visualization API. The browser loaders reconstructed and injected obfuscated second-stage web-skimming code from spreadsheet cells.
A cryptocurrency-stealing campaign began using ClickFix-style lures that claimed to expose nonexistent API flaws at cryptocurrency swap services. Early lures directed victims to execute JavaScript in Chrome rather than operating-system commands.
ClearFake activity was again observed in early June, including a PowerShell stage that queried system temperature through WMI and exited when no temperature was returned, an anti-virtualization or sandbox-evasion measure.
Proofpoint observed TA571 using lure language resembling ClearFake's root-certificate warnings. The campaign delivered either DarkGate through an HTA file or NetSupport RAT through a ZIP file.
The custom iframe content on pley[.]es was replaced with the ClearFake inject. The ClearFake content remained served from the site into early June.
ClearFake campaigns used an initial PowerShell script that flushed DNS, cleared the clipboard, displayed a decoy message, and retrieved an additional in-memory PowerShell stage. Later stages deployed a ZIP archive, side-loaded a trojanized DLL, and ultimately delivered Lumma Stealer and additional payloads including Amadey and XMRig-related malware.
Researchers identified the related ClickFix activity cluster on compromised sites using an iframe hosted on pley[.]es. The lure presented a fake browser-update error that instructed victims to run malicious PowerShell as an administrator, ultimately leading to Vidar Stealer.
ClearFake was observed using compromised websites and fake browser or certificate warnings to copy malicious PowerShell commands to victims' clipboards. Its infection chain used EtherHiding-hosted scripts and Keitaro TDS infrastructure to deliver multiple malware payloads.
TA571 launched a campaign of more than 100,000 messages targeting thousands of organizations globally. HTML attachments impersonated Microsoft Word content and induced victims to paste clipboard-copied PowerShell commands, delivering Matanbuchus or DarkGate.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcemalware.news
Open sourceblog.talosintelligence.com
Open sourcecyberveille.ch
Open sourcebolster.ai
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.