Cisco Talos identified two new campaigns utilizing ClickFix attacks, a method where victims are tricked into copying and executing malicious code on their own devices. These attacks leverage trusted services and familiar online experiences to conceal malicious activity, making them harder to detect, according to a recent report by TahawulTech.
The first campaign, active since October 2025, targets cryptocurrency traders by luring them with fake security reports. Victims are instructed to paste JavaScript into their Chrome browser, which then fetches the main attack code from a public Google spreadsheet. This malware can alter cryptocurrency deposit addresses and display fake bonuses, with at least $10,000 in Bitcoin traced to 49 addresses. The second campaign, observed in April 2026, uses fake Google verification prompts delivered via a compromised website. This leads to the installation of the Amatera information stealer, capable of harvesting credentials, cryptocurrency, and disabling security software. Cisco recommends organizations strengthen browser controls, monitor application requests, and educate users that legitimate verification processes do not require manual command execution.
Source: TahawulTech
