Skip to content

Product1 publisher3 min readPublished

Talos found ClickFix operators moving their skimmer into a Tampermonkey userscript

The lure is a fake leaked vulnerability report promising 38% higher payouts to anyone greedy enough to paste the code. The command channel is a public Google Sheet that Talos reported twice and that stayed up.

The Product Desk · Product desk

What happened

  • Cisco Talos documented a ClickFix campaign that never asks the victim to run anything against Windows, instead walking them through pasting JavaScript into the Chrome address bar or installing it into the Tampermonkey extension.
  • The second campaign starts on a compromised site where a Cloudflare Worker injects ClearFake JavaScript stored in a BNB Smart Chain smart contract, letting the operators swap the payload without touching the site again.
  • Both loaders end in Amatera, whose configuration in one branch ran to more than 400 collection entries covering browsers, messaging apps, password managers and over 100 desktop wallet locations.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint A control set built around the Run dialog and PowerShell has nothing to inspect when the whole chain is one browser tab and one request to a Google domain, so the coverage gap shows up as silence rather than as an alert someone can triage.
  • exposure The swap services absorb the support tickets and the blame for thefts carried out against their own API responses inside a customer's browser, while their server-side logs show a session that looks entirely ordinary.
  • precedent Free unauthenticated reads of any published sheet turn Google's own domain into a resupply channel that outlives reporting, which makes takedown a recurring chore for defenders rather than a resolution.
  • cost The Windows branch prices the victim differently: Amatera's collection reach into password managers, authenticator apps and wallet files means the loss is not bounded by whatever the address swap diverted.

The lure does the selection work. A fake leaked vulnerability report, seeded through Telegram, the cybercrime forum DarkForums and paste sites, describes an API flaw that does not exist [8]. The SwapZone version promised roughly 38% higher payouts; the SimpleSwap rewrite offered a 25% loyalty bonus supposedly triggered by a validation gap in a loyalty endpoint [9]. Someone recruited that way believes he is the one doing the exploiting, and the awareness slide about fake update prompts does not cover him. Once the code is running, it hooks the browser's fetch API, replaces cryptocurrency deposit addresses in server responses and in the clipboard, and renders counterfeit bonus elements into the page so the numbers the victim came for appear to be there [4].

The take is small. Payments reached 24 of the 49 bitcoin addresses Talos found, 0.159 bitcoin in total, worth about $10,000 in early August [10][11]. That works out to roughly $417 per address that saw money [1], and across April to the end of June, the window Talos could deobfuscate, roughly $3,300 a month [3]. Talos says it could not recover samples from before April, so the real total is higher [13]. Even read as a floor, this is a small business that required no infrastructure the operators had to pay for.

Command and control is a spreadsheet. The Google Visualization API, a Google Docs feature dating to 2008, gives free unauthenticated read-only access to any publicly published sheet through a query in a URL [6]. The payload sat in one, formatted white on white and pushed thousands of rows down, fetched by the browser from docs.google.com in the middle of an otherwise normal session [7]. Talos reported the documents in April and the campaign was back on a new sheet inside a week [14]. When paste.sh began automatically detecting the first-stage script in July, the operators moved that script into a Google Doc as well; the documents were reported again and were still active on Aug. 11 [15]. A paste site shipped automated detection in that period, and Google's answer was per-document removal [15].

For anyone who has to answer for detection coverage, the grid has two axes: where the payload executes, and whether its destination is already allowlisted. Everything the ClickFix playbook trained teams to catch sits in one corner, an OS process spawned from the Run dialog reaching unfamiliar infrastructure. That is the second campaign here, with a fake Google CAPTCHA, a WebDAV path on a randomized subdomain and a disguised DLL loaded through rundll32 by function ordinal [17]. The browser-only campaign sits in the corner with no sensor in it: execution in page context, destination docs.google.com, theft performed inside the customer's browser against the service's own responses [4][7].

The levers that remain are not in the endpoint console. One is which extensions can install on a managed browser, since the Tampermonkey version reloads the code on every visit to the targeted site [3]. The other is whether a deposit address can be confirmed somewhere other than the page displaying it, because the page is the thing lying. Both are product decisions, and both get made long before the incident.

What to watch

  • Whether Google adds abuse detection to the Visualization API read path instead of removing published documents one at a time.
  • Whether SwapZone or SimpleSwap ship a deposit address confirmation step that does not rely on the page the victim is looking at.
  • Whether Talos recovers pre-April samples that would push the 0.159 bitcoin total upward.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories