ClickFix Campaigns Have Used Trusted Services for Theft

Attackers are exploiting legitimate cloud tools to hide malicious scripts and compromise cryptocurrency wallets.

Updated on Oct. 6, 2026 in Cybersecurity

Bold flat-color editorial illustration featuring a navy conduit structure with a single red hidden geometric node, representing digital threat concealment.
Cisco Talos reports that cyberattackers are increasingly leveraging legitimate cloud services and fake prompts to execute credential theft and deploy malicious scripts. AI Illustration. Upload story photo >

Live Poll

Do you feel confident identifying fake security verification prompts while browsing the web?

Cisco Talos has reported on two ongoing ClickFix cyberattack campaigns that leverage trusted services to bypass security filters. These attacks deceive users into running malicious code to facilitate cryptocurrency theft and credential harvesting.

Why it matters

By repurposing widely used platforms like Google Sheets and fake CAPTCHA prompts, attackers effectively mask their infrastructure from traditional security monitors. This shift complicates threat detection as malicious payloads are delivered through legitimate, high-trust traffic.

The first campaign used Google Sheets to obfuscate malicious JavaScript, while the second deploys the Amatera information stealer to access browser data and over 100 different cryptocurrency wallets on Windows machines.

The players

Cisco Talos

A global threat intelligence unit that maintains deep visibility into network telemetry and vulnerability research.

The details

In these attacks, victims are coerced into pasting malicious JavaScript directly into browser address bars or developer extensions. This code then retrieves secondary payloads from public cloud services or blockchains. The second campaign further compromises systems by installing hidden commercial remote support software, granting attackers persistent, unauthorized access to the host machine.

Timeline

  1. October 2025: The first cryptocurrency scam campaign began operating.

  2. April 2026: Talos shared findings and the second investigation began.

  3. August 2026: The first campaign remained active.

The Tech Race

This activity follows a pattern of threat actors increasingly prioritizing the abuse of trusted, high-reputation services to evade modern security filters. As defensive AI and heuristic monitoring improve, attackers are pivoting toward these 'living-off-the-land' techniques that leverage the essential trust foundations of the web.

Users should exercise extreme caution when prompted to paste code into their browser address bar or install unexpected remote support software, as these are primary infection vectors. Security teams should monitor for unauthorized use of cloud-hosted scripts and verify the origin of all interactive elements like CAPTCHA prompts.

The takeaway

The effectiveness of these campaigns relies on users manually executing code under the guise of fake bonuses or security checks. Monitor your security logs for unconventional script execution, specifically looking for JavaScript or remote support tools initiated via browser-based user actions.

Further reading

For broader context on how modern threats evolve to exploit enterprise infrastructure, visit our Cybersecurity section.

Live Poll

Do you feel confident identifying fake security verification prompts while browsing the web?