Threat intelligence researchers from Cisco Talos have examined ClickFix attacks, revealing how threat actors manipulate trusted web services to compromise computer systems and steal digital assets. The findings, published from Riyadh, show cyber criminals using familiar platforms and fake verification prompts to deceive users into copying and executing malicious commands directly on their devices.

The investigation outlines methods where attackers blend hostile actions into normal network activity. In one instance, cryptocurrency traders were tricked into pasting code into their web browsers, which subsequently retrieved payloads from a public Google spreadsheet. In another campaign, fake verification prompts led to credential theft and remote access to infected computers.

Misuse of Trusted Web Services

Security analysts observed that attackers frequently hide malicious operations within legitimate enterprise destinations. Consequently, traditional network filters often fail to block these interactions because the destination domains are approved for daily corporate use.

“Attackers are increasingly finding ways to hide malicious activity within trusted services and familiar online experiences, making it more difficult to distinguish malicious behavior from legitimate activity. Organizations should look beyond whether a destination itself is trusted and focus on which applications are making requests, strengthen controls around browsers and extensions and reinforce awareness around prompts asking users to copy and run commands on their devices.”

Fady Younes, Managing Director, Cybersecurity, Cisco METAC

Cryptocurrency Fraud via Google Spreadsheets

The first operation tracked by Talos began in October 2025 and focused on cryptocurrency traders. Specifically, attackers circulated a fake leaked security document on Telegram, forums, and text-sharing sites, promising a 25% currency swap bonus. Victims were instructed to paste JavaScript into the address bar of Google Chrome or embed it into legitimate browser extensions.

The script retrieved a payload from a public Google spreadsheet where commands were disguised as white text on a white background. Furthermore, the malware modified recipient addresses during transfers and displayed fake bonus confirmations. Talos traced 49 Bitcoin addresses connected to the operation, with 24 addresses collecting at least $10,000 before moving funds across 3,000 other addresses. Although the control documents were taken down in April 2026, operators resumed activity with new spreadsheets through August 2026.

ClearFake Chain and Amatera Information Stealer

A separate inquiry initiated in April 2026 followed suspicious activity at a European government organization. Talos determined the incident was part of a wider theft campaign linked to the ClearFake infection chain. In this process, compromised websites obtained commands from a public blockchain and served victims with a fake Google CAPTCHA prompt.

When victims executed the supplied command on Windows computers, the action installed the Amatera information stealer. The tool extracted stored credentials, data from messaging apps, password records, and information from more than 100 cryptocurrency wallets. Secondary payloads also disabled security software and established hidden remote support utilities on infected machines.

Defenses Against ClickFix attacks

To mitigate the risks of ClickFix attacks, enterprise cybersecurity teams must manage browsers and browser extensions with strict device management policies. In addition, security staff should monitor outbound collaboration requests and inspect third-party components operating on public websites. Organizations must also train employees that authentic verification dialogues never require manual command execution in local terminal prompts.