Hackers Abuse Google Sheets as C2 in ClickFix Attacks to Steal Cryptocurrency

Published September 9, 2026

Attackers are using fake Google Sheets links to steal cryptocurrency. They trick users into opening a malicious link that loads hidden code into their browser, then steals their crypto wallet keys.

Report priority
Medium
Targets
Google

How it works

  • Attackers send victims a fake Google Sheets link that looks like a legitimate crypto-related offer or update.
  • When users click it, their browser loads hidden JavaScript code from a Google Sheet.
  • That code then steals their crypto wallet keys and sends them to the attacker's server.

What to do

If you clicked a Google Sheets link in a phishing email or message and saw no warning before opening it, check your browser's address bar for unusual Google Sheets links or unexpected pop-ups after clicking a crypto-related message. If you suspect you clicked a malicious link, monitor your crypto wallet for unauthorized transactions.

If you clicked a suspicious link, immediately log out of your crypto wallet and check for unauthorized activity. Enable two-factor authentication on your wallet and review recent transactions. If you suspect your wallet was compromised, contact the wallet's support team or a trusted security expert for help. Avoid clicking crypto-related links from unknown senders in the future.

Technical details

An attacker sends a phishing email with a link to a Google Sheet titled 'Your Crypto Wallet Update Required.' When a victim clicks the link, their browser loads a hidden script that steals their crypto wallet keys and sends them to the attacker's server.

A cryptocurrency-stealing campaign that abuses Google Sheets and the Google Visualization API as a covert command-and-control channel, delivering obfuscated JavaScript directly into victims’ browser sessions.