Close Menu
    What's New

    UAE Embassy in Maldives organises roundtable to strengthen UAE–Maldives cooperation in energy sector

    October 6, 2026

    Kenya confirms its first Ebola case as patient dies after arriving from DR Congo

    October 6, 2026

    Cisco Talos reveals how ClickFix campaigns are hiding malicious activity in trusted platforms

    October 6, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    The Gulf GazetteThe Gulf Gazette
    • Home
    • KSA
    • UAE
    • GCC
    • Technology
    • Lifestyle
    • Sports
    The Gulf GazetteThe Gulf Gazette
    Home»Technology»Cisco Talos reveals how ClickFix campaigns are hiding malicious activity in trusted platforms
    Technology

    Cisco Talos reveals how ClickFix campaigns are hiding malicious activity in trusted platforms

    Editorial TeamBy Editorial TeamOctober 6, 2026
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Fady Younes, Managing Director, Cybersecurity, Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia (METAC) at Cisco.

    Cisco Talos, Cisco’s threat intelligence organisation, has published findings from two investigations into ClickFix attacks, a technique that persuades victims to copy and run malicious code on their own computers.

    The investigations show how attackers are using services that organisations already trust and allow through their networks to conceal malicious activity. In one campaign, cryptocurrency traders were persuaded to paste code into Chrome that retrieved the main attack code from a public Google spreadsheet. In a separate campaign, a fake Google verification prompt led to stolen credentials, cryptocurrency theft and remote access to compromised machines.

    “Attackers are increasingly finding ways to hide malicious activity within trusted services and familiar online experiences, making it more difficult to distinguish malicious behaviour from legitimate activity”, said Fady Younes, Managing Director, Cybersecurity, Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia (METAC) at Cisco. “Organisations should look beyond whether a destination itself is trusted and focus on which applications are making requests, strengthen controls around browsers and extensions and reinforce awareness around prompts asking users to copy and run commands on their devices”.

    Example One: A cryptocurrency scam leveraging Google Sheets

    The first campaign has been operating since October 2025 and targets cryptocurrency traders. The bait is a fake leaked security report claiming a vulnerability at two currency swap sites could provide a bonus of 25% or more. Talos identified the lure circulating across Telegram, criminal forums and text-sharing sites.

    Victims are instructed to paste JavaScript into the Chrome address bar or add it to a legitimate browser extension so that it reloads on every visit. The pasted code then retrieves the main malicious payload from a publicly published Google spreadsheet, where the operators concealed the code using white text on a white background.

    The resulting malware can rewrite the cryptocurrency deposit address displayed on a trading page, replace addresses copied by the victim and display a convincing fake bonus on screen.

    Talos traced 49 Bitcoin addresses associated with the campaign, 24 of which collected victim funds worth at least approximately US$10,000 before the funds were moved through more than 3,000 additional addresses. Talos notes that the actual figure is likely higher because samples from the earliest phase of the campaign were unavailable.

    After Talos shared its findings with Google and the affected sites in April 2026, the identified lure and control documents were removed. Approximately one week later, the campaign resumed using a new spreadsheet, with later versions remaining active into August despite being repeatedly flagged.

    Example Two: Fake verification prompts lead to credential theft and remote access

    The second investigation began in April 2026 after Talos observed unusual activity at a European government organisation. Talos assesses with moderate confidence that the activity formed part of a broader cryptocurrency and credential theft operation rather than an attack specifically targeting that organisation.

    In this campaign, malicious code planted on a compromised website, in an infection chain linked to ClearFake, retrieves its next instructions from a public blockchain. Victims are then presented with a fake Google CAPTCHA and instructed to paste a command into Windows.

    The command installs the Amatera information stealer, which can harvest browser data, messaging applications, more than 100 cryptocurrency wallets, password managers and files containing private keys.

    Follow-on payloads can also disable security software, turn the compromised machine into a relay for attacker traffic and install a hidden copy of commercial remote support software.

    Strengthening defences against ClickFix attacks

    Cisco Talos highlights several steps organisations can take to reduce exposure to these techniques.

    Organisations should manage browsers with the same level of control applied to laptops, including controlling which extensions employees can install. Security teams should also monitor requests to cloud collaboration services from applications or browser sessions that have no reason to make them and review third-party components running on customer-facing websites for unusual activity.

    Organisations can also reinforce employee awareness with a simple principle: legitimate verification processes should not require users to copy a command and manually run it on their device.

    Both Cisco Talos reports include detection guidance and technical indicators for security teams.

    Read the full analysis of the browser-based cryptocurrency campaign (here) and the ClearFake infection chain (here).

    Image Credit: Cisco


    Source: Tahawul Tech

    Previous ArticleFANR Board of Management reviews key regulatory, strategic developments
    Next Article Kenya confirms its first Ebola case as patient dies after arriving from DR Congo

    Related Posts

    UAE Embassy in Maldives organises roundtable to strengthen UAE–Maldives cooperation in energy sector

    October 6, 2026

    NetApp to showcase AI-ready data infrastructure as CEO George Kurian takes the stage at Ai Everything Abu Dhabi 2026

    October 6, 2026

    Deriv and BITS Pilani Dubai Campus sign MoU to strengthen AI and talent partnership

    October 6, 2026
    Latest Posts

    UAE Embassy in Maldives organises roundtable to strengthen UAE–Maldives cooperation in energy sector

    October 6, 2026

    Kenya confirms its first Ebola case as patient dies after arriving from DR Congo

    October 6, 2026

    Cisco Talos reveals how ClickFix campaigns are hiding malicious activity in trusted platforms

    October 6, 2026

    FANR Board of Management reviews key regulatory, strategic developments

    October 6, 2026
    Don't Miss

    UAE Embassy in Maldives organises roundtable to strengthen UAE–Maldives cooperation in energy sector

    By Editorial TeamOctober 6, 2026

    MALÉ, 6th October, 2026 (WAM) — The Embassy of the United Arab Emirates in the…

    Austria’s inflation rate up by 0.9% to 3.1% in March

    April 1, 2026

    Saudi FM, UN chief discuss regional developments in phone call

    April 1, 2026
    2026. All rights reserved.
    • KSA
    • UAE
    • GCC
    • Technology
    • Lifestyle
    • Sports
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.