Cisco Talos says ClickFix attackers used Google Sheets to deliver cryptocurrency-stealing browser code

Attackers are using fake troubleshooting prompts to trick people into pasting malicious code from a Google Sheet into their browser, leading to cryptocurrency theft. Cisco Talos says the campaign uses a ClickFix-style social-engineering lure and abuses a legitimate Google service as delivery infrastructure; the pasted code alters transaction pages in Chrome or helps install a malicious browser extension to steal or manipulate crypto transactions.
Why it matters: People who handle cryptocurrency are at immediate risk of losing funds if they follow browser 'fix' instructions from pop-ups or messages. Users should avoid pasting code into browser consoles, remove unknown extensions, and review wallets and browser sessions for tampering.

Sources

ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Elizabeth Montalbano 2026.09.08 100% relevant
This article appears to be the first tracked report here describing this specific ClickFix campaign that uses public Google Sheets as delivery infrastructure for browser-based crypto theft.
← Back to all stories