- What: ClickFix campaigns use social engineering to steal credentials and cryptocurrency
- Impact: Organizations are at risk of long-term network compromise
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources ENDPOINT SECURITY CYBERATTACKS & DATA BREACHES REMOTE WORKFORCE THREAT INTELLIGENCE NEWS ClickFix Campaigns Abuse Legitimate Services for Persistent Access Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic. Elizabeth Montalbano,Contributing Writer September 8, 2026 5 Min Read SOURCE: RAWPIXEL.COM VIA SHUTTERSTOCK Two recently uncovered campaigns use ClickFix-style attacks to steal credentials and cryptocurrency as well as to go deeper into the enterprise network to maintain long-term persistence in compromised systems. The attacks, while separate, demonstrate how threat actors continue to evolve the social engineering tactic to exploit commonly used services and engage in more complex malicious activities. Researchers from Cisco Talos discovered both campaigns, which use different delivery methods, but both rely on the victim to take a seemingly routine action to compromise themselves, according to two separate reports by the networking firm's threat research lab published today. The link between the two was not only in their use of social engineering attacks, commonly known as ClickFix and ClearFake, but also in how they abused legitimate services and assets to make the malicious activity resemble typical user or application behavior, according to the researchers. Related:ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain "Both operations turn the victim into an active part of the infection chain and abuse services or technologies that users and defenders normally regard as legitimate," Vanja Svajcer, senior threat researcher at Cisco Talos, tells Dark Reading. "They also show attackers moving into places where conventional network detection has less context, like browser sessions, trusted cloud services, public blockchain infrastructure, and signed or legitimate software components." New Attacks Demonstrate ClickFix Diversity In one attack, aimed at stealing cryptocurrency, threat actors used a ClickFix-style approach to coerce users into pasting malicious code that can alter transaction interface pages in Chrome or add it through a browser extension. In a deviation from typical ClickFix attacks, the attackers convince potential victims to retrieve and enter malicious browser code from a publicly available Google Sheet, using a legitimate Google service as part of their infrastructure. The other attack on a Ukrainian government organization by a Russian threat actor used what is known as a ClearFake and shows victims a phony Google CAPTCHA, instructing them to run a malicious command. That command executes various malware that can steal cryptocurrency and credentials, deploy a reverse proxy, and install an unauthorized remote access tool. Together, the attacks demonstrate the evolution of these related social engineering approaches and how a single deceptive prompt can open the door to financial theft, credential theft, and deeper compromise, the researchers said. Related:'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month Abusing Legitimate Google Services The first campaign started as early as October 2025 as a direct attack on the browser and evolved significantly by March 2026 to compromise Google services too, the researchers wrote. "This campaign uses a twist on the tactics associated with 'ClickFix' social engineering attacks, in which targets are manipulated into copying and pasting PowerShell or other commands and executing them to launch malware," Sean Gallagher, security research engineer at Cisco Talos, explained in the report on the campaign. "But instead of targeting the operating system of the victim's device, the actors behind this campaign aim to convince the user to inject malicious code into their own browser session." Threat actors used lures to get targets to paste a code snippet directly into the Chrome Web browser's navigation bar; however, by the latest version, the attackers were focused on a legitimate Chrome plug-in, TamperMonkey, "to inject a loader script pasted in by the user and [to] provide persistence across sessions with the current targeted site," he wrote. Later versions of the attack also began using the Google Visualization API to deliver malicious scripts stored in a Google Sheets document, Gallagher wrote. Then, after frequent disruption of their posts on shared text sites, the actors moved in July to hosting all the components of their campaign in Google Docs and Google Sheets, according to Gallagher. Related:15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning Ukrainian Government Impacted The discovery of a second attack on a Ukrainian government entity began in April 2026 with an investigation into a DLL called verification.google executing from WebDAV at that organization, according to the report. Upon further scrutiny, the researchers traced an attack that started with a compromised website displaying a fake Google CAPTCHA that uses the ClickFix technique to trick victims into pasting a command into the Windows Run dialog. That command retrieves a disguised dynamic link library (DLL) file over WebDAV and launches the Amatera infostealer, which can harvest cryptocurrency data, credentials, browser information, and sensitive files. One branch of the malware also deployed a cryptocurrency stealer and reverse proxy, while another installed NetSupport Manager to give attackers remote control of the infected system, according to the report. Though just one organization prompted the investigation, the researchers eventually realized that "the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload," Svajcer wrote in the post. Defending Against ClickFix Variants Researchers from Proofpoint first spotted ClickFix attacks about two years ago, and the technique has become a favorite of the cybercriminal community since then. The ultimate aim of the attack is to trick a user into executing malicious prompts against themselves, which is why they are such a successful vector for attackers. "Both of these campaigns abuse services defenders already trust, Google Sheets, Cloudflare Workers, public blockchain endpoints, for command and control," observes Denis Calderone, principal and chief technology officer at Suzu Labs. "The malicious traffic looks like normal business activity, so domain-based blocking isn't going to catch it." Indeed, as these and other recently discovered ClickFix attacks demonstrate, new attacks that leverage this malicious prompt as the initial vector are starting to find their way deeper in the network and other services. Not only are threat actors using these prompts to launch infostealers to harvest credentials, they're increasingly aiming to achieve both network persistence as initial access brokers for potential ransomware attacks, as well as financial gain through cryptocurrency theft. To defend against these threats, Cisco Talos included indicators of compromise (IoCs) for each attack in the respective reports. As a general rule, the researchers also recommend that organizations take steps to more closely manage users' browsers, limiting use of developer-level functionality and deployment of browser extensions based on role. "Defenders should treat the browser as a managed execution environment, not simply as a tool used to reach websites," Svajcer says. Another defense measure is to warn employees and customers of social engineering techniques and the dangers of modifying browser behavior through copy-and-paste code, he adds. Specifically, Svajcer says they should "educate users that no legitimate CAPTCHA, verification workflow, vulnerability report or support process should require them to paste code into the address bar, an extension, the Run dialog, PowerShell, or a terminal." About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Threat Exposure Analytics: Measuring and Communicating Security Risk Building an Effective Red Team: Beyond Penetration Testing How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security More Webinars You May Also Like ENDPOINT SECURITY Swipe, Plug-in, Pwned: Researchers Find New Ways to Hack Vehicles by Robert Lemos JAN 23, 2026 ENDPOINT SECURITY 2 Separate Campaigns Probe Corporate LLMs for Secrets by Elizabeth Montalbano JAN 12, 2026 ENDP