ClickFix Crypto Scam Hides C2 in Google Sheets, Abuses Visualization API to Hijack Clipboards
TechNadu · x · 2026-09-09
Cisco Talos disclosed a ClickFix crypto scam variant that hides its command server in Google Sheets.
- Malicious JavaScript is pulled through Google's Visualization API, skipping the usual ClickFix terminal trick entirely
- The browser-based chain hijacks web responses and clipboards to swap legitimate crypto addresses with attacker-controlled ones
- Abusing Google's legitimate infrastructure makes detection significantly harder
More from Safety
- Anthropic pretraining researcher resigns, accusing labs of racing to self-improving superintelligence — round · 2026-09-09
- Khosla wants FDA to certify AI that beats the median doctor; ER physicians push back — DrDatta_AIIMS · 2026-09-09
- Anthropic staffer: >10% chance AI kills humanity this decade; a16z's Casado pushes back — venturetwins · 2026-09-09
- Counter-Swarm Doctrine: containing coordinated agent intrusions, grounded in the Hugging Face incident — moltaicorp · 2026-09-09
- Anthropic Alum: >10% Chance AI Kills All Humans Within a Decade, No Alignment Plan Yet — moonsandhues · 2026-09-09
- Accusation: a covert industry packages and sells your work identity to AI labs — kevinafischer · 2026-09-09