Hackers Abuse Google Sheets as C2 in ClickFix Attacks to Steal Cryptocurrency
Attackers are using fake Google Sheets links to steal cryptocurrency. They trick users into opening a malicious link that loads hidden code into their browser, then steals their crypto wallet keys.
- Report priority
- Medium
- Targets
How it works
- Attackers send victims a fake Google Sheets link that looks like a legitimate crypto-related offer or update.
- When users click it, their browser loads hidden JavaScript code from a Google Sheet.
- That code then steals their crypto wallet keys and sends them to the attacker's server.
What to do
If you clicked a Google Sheets link in a phishing email or message and saw no warning before opening it, check your browser's address bar for unusual Google Sheets links or unexpected pop-ups after clicking a crypto-related message. If you suspect you clicked a malicious link, monitor your crypto wallet for unauthorized transactions.
If you clicked a suspicious link, immediately log out of your crypto wallet and check for unauthorized activity. Enable two-factor authentication on your wallet and review recent transactions. If you suspect your wallet was compromised, contact the wallet's support team or a trusted security expert for help. Avoid clicking crypto-related links from unknown senders in the future.
Technical details
An attacker sends a phishing email with a link to a Google Sheet titled 'Your Crypto Wallet Update Required.' When a victim clicks the link, their browser loads a hidden script that steals their crypto wallet keys and sends them to the attacker's server.
A cryptocurrency-stealing campaign that abuses Google Sheets and the Google Visualization API as a covert command-and-control channel, delivering obfuscated JavaScript directly into victims’ browser sessions.