ClickFix Campaigns Have Used Trusted Services for Theft
Attackers are exploiting legitimate cloud tools to hide malicious scripts and compromise cryptocurrency wallets.
Updated on Oct. 6, 2026 in Cybersecurity

Live Poll
Do you feel confident identifying fake security verification prompts while browsing the web?
Cisco Talos has reported on two ongoing ClickFix cyberattack campaigns that leverage trusted services to bypass security filters. These attacks deceive users into running malicious code to facilitate cryptocurrency theft and credential harvesting.
Why it matters
By repurposing widely used platforms like Google Sheets and fake CAPTCHA prompts, attackers effectively mask their infrastructure from traditional security monitors. This shift complicates threat detection as malicious payloads are delivered through legitimate, high-trust traffic.
The first campaign used Google Sheets to obfuscate malicious JavaScript, while the second deploys the Amatera information stealer to access browser data and over 100 different cryptocurrency wallets on Windows machines.
The players
Cisco Talos
A global threat intelligence unit that maintains deep visibility into network telemetry and vulnerability research.
The details
In these attacks, victims are coerced into pasting malicious JavaScript directly into browser address bars or developer extensions. This code then retrieves secondary payloads from public cloud services or blockchains. The second campaign further compromises systems by installing hidden commercial remote support software, granting attackers persistent, unauthorized access to the host machine.
Timeline
October 2025: The first cryptocurrency scam campaign began operating.
April 2026: Talos shared findings and the second investigation began.
August 2026: The first campaign remained active.
The Tech Race
This activity follows a pattern of threat actors increasingly prioritizing the abuse of trusted, high-reputation services to evade modern security filters. As defensive AI and heuristic monitoring improve, attackers are pivoting toward these 'living-off-the-land' techniques that leverage the essential trust foundations of the web.
Users should exercise extreme caution when prompted to paste code into their browser address bar or install unexpected remote support software, as these are primary infection vectors. Security teams should monitor for unauthorized use of cloud-hosted scripts and verify the origin of all interactive elements like CAPTCHA prompts.
The takeaway
The effectiveness of these campaigns relies on users manually executing code under the guise of fake bonuses or security checks. Monitor your security logs for unconventional script execution, specifically looking for JavaScript or remote support tools initiated via browser-based user actions.
Further reading
For broader context on how modern threats evolve to exploit enterprise infrastructure, visit our Cybersecurity section.
Live Poll
Do you feel confident identifying fake security verification prompts while browsing the web?






