Skip to content

UPDATED 06:00 EDT / SEPTEMBER 08 2026

SECURITY

ClickFix moves into the browser and onto WebDAV, Cisco Talos finds

Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the copy-and-paste PowerShell prompt it is known for, one that never touches the operating system at all and one that ends in a stealer plus whichever follow-on payload the operators choose to task.

ClickFix emerged in 2024 and has become known for one move: a page claiming some check has failed and offering a command for the visitor to paste into the Windows Run dialog or a Mac terminal. Having the target run the code sidesteps the download warnings and email filtering that catch attachments. The technique has spread quickly since, turning up last month in a fake OpenAI Codex installer aimed at Mac users that Cato Networks Ltd. documented.

In the first of the campaigns Talos detailed, the target is never asked to run anything against Windows. The lure walks the victim through pasting JavaScript into the Chrome address bar, or in a later version installing it into the Tampermonkey browser extension, which reloads the code on every visit to the targeted site.

What the code does is skim. It hooks the browser’s fetch application programming interface, replaces cryptocurrency deposit addresses in server responses and in the clipboard, and renders counterfeit “bonus” elements into the page to account for the numbers the victim is seeing. Talos observed the campaign against swap service SwapZone.io and later the trading aggregator SimpleSwap.io.

Command and control runs through the Google Visualization API, a Google Docs feature dating to 2008 that gives free, unauthenticated read-only access to any publicly published Google Sheet through a query embedded in a URL. The operators hid obfuscated payload code in a sheet by formatting the text white on white and pushing the rows thousands of lines down. Requests for it come from the browser, to docs.google.com, in the middle of an otherwise normal session.

The lure is a fake leaked vulnerability report describing an API flaw that does not exist, seeded through Telegram, the cybercrime forum DarkForums and paste sites. The intended victims are people willing to exploit it: The SwapZone version promised roughly 38% higher payouts, the SimpleSwap rewrite a 25% loyalty bonus triggered by a validation gap in a loyalty endpoint.

Talos found 49 bitcoin addresses in the campaign, 30 of them repeating across most of the samples it deobfuscated between April and the end of June. Payments reached 24 of those addresses, 0.159 bitcoin in total, worth about $10,000 in early August. Money moved out through 30 further wallets and then through transactions involving more than 3,000 addresses, consistent with a mixing operation. Talos said it could not recover samples from before April, so the total is likely higher.

Takedowns have not held. Talos reported the documents to Google and to both sites in April, and the campaign was back on a new sheet within a week. After paste.sh began automatically detecting the first-stage script in July, the operators moved that script into a Google Doc as well. The Google documents were reported again and remained active as of Aug. 11.

The second campaign likely starts on a compromised website where a malicious Cloudflare Worker injects ClearFake JavaScript. That code is stored in a BNB Smart Chain smart contract and retrieved at page load, a technique called EtherHiding that lets the operators swap the payload without touching the site. On Windows it overlays a fake Google CAPTCHA and instructs the visitor to open the Run dialog, paste and press Enter.

The pasted command opens a WebDAV path on a randomized subdomain and executes a disguised DLL through rundll32 by function ordinal. Talos started the investigation after seeing the same WebDAV execution pattern at a Ukrainian government organization in April, and assesses with moderate confidence that the attacks were not targeted at any particular organization. It tracks the actor behind the “verification.google” activity as UAT-10820.

Both loaders deliver Amatera, an infostealer whose configuration in the verification.google branch ran to more than 400 collection entries covering browsers, extensions, messaging apps including Telegram, Signal and WhatsApp, password managers including KeePass, Bitwarden and 1Password, more than 100 desktop wallet locations, authenticator apps and VPN clients. Four file grabber rules sweep the desktop, downloads, documents and recent items for private keys, wallet backups, API tokens and certificate files.

The follow-on payloads diverge. One branch sideloads a malicious NativeAOT library through a signed Google Chrome component, and that library loads ZigCryptoStealer, a clipboard hijacker written in Zig that pulls its own command and control domain from a second BNB Smart Chain contract and drops a legitimate but vulnerable signed driver it abuses to terminate security software from kernel mode. A separate task runs a Go reverse TCP proxy in memory.

The other branch runs PowerShell that checks volume serial numbers, uptime, timing, processor count, memory and video adapter names for signs of a sandbox, generates decoy traffic to GitHub, npm, PyPI, Docker Hub and NuGet, then installs a renamed copy of the NetSupport Manager remote access tool configured to hide its interface and poll a gateway every 60 seconds. That gateway resolved to an address in Russia, which Talos cited in assessing with moderate confidence that a Russian actor was behind the “verification.google” attacks.

The ZigCryptoStealer contract gives a rough sense of scale. It was deployed on March 16 and its operator updated the stored domain 39 times through July 26, cycling six domains during July alone. Cisco Umbrella recorded queries for the most recent of them from 98 countries, most often the United States, Indonesia, Brazil, India and Egypt.

Talos was blunt about the reach of the crypto skimmer. “While this campaign doesn’t pose a specific threat to most organizations, the approaches that the actors here are using do,” the researchers wrote, pointing at supply-chain attacks on e-commerce and other customer-facing systems. Its recommendations run to browser management, restricting extension installation by role and monitoring for requests to docs.google.com from processes and sessions with no other Google Docs activity.

Image: SiliconANGLE/GPT Image 2

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/

 

About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.
  • Max. file size: 244 MB.

Sign in

SIGN IN

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry