Cisco Talos Uncovers ClickFix Evolution: Browser-Based Attacks and WebDAV Exploitation
Cisco's threat intelligence team has identified two sophisticated variants of the ClickFix attack technique that move beyond traditional PowerShell prompts, including a browser-based cryptocurrency skimmer and a WebDAV-based loader delivering multiple malware families.

Researchers at Cisco Systems Inc.'s Talos Threat Intelligence group have uncovered two distinct ClickFix campaigns that represent a significant evolution of the attack method that emerged in 2024. Rather than relying solely on the copy-and-paste PowerShell commands the technique became known for, these new variants either bypass the operating system entirely or employ WebDAV paths to execute malicious code.
Since its introduction last year, ClickFix has gained notoriety for a straightforward social engineering approach: displaying fake error messages that prompt users to paste commands into the Windows Run dialog or Mac terminal. This method circumvents traditional security controls like download warnings and email filters that typically block file attachments. The tactic gained further visibility when researchers at Cato Networks Ltd. documented a variant disguised as a fake OpenAI Codex installer targeting Mac users.
Browser-Based Cryptocurrency Skimming Campaign
The first campaign identified by Talos never requires victims to execute anything on their Windows systems. Instead, the attack lures users into pasting JavaScript code directly into the Chrome address bar or, in later iterations, installing it as a Tampermonkey browser extension that executes the malicious code on every visit to targeted websites.
The injected code functions as a sophisticated skimmer. It intercepts the browser's fetch application programming interface, swaps out legitimate cryptocurrency deposit addresses in both server responses and clipboard contents, and injects fake "bonus" elements into the page to match the altered numbers displayed to victims. Talos observed this campaign targeting the cryptocurrency swap service SwapZone.io and later the trading platform SimpleSwap.io.
Command and control infrastructure leverages the Google Visualization API, a Google Docs feature from 2008 that provides free, unauthenticated read-only access to publicly shared Google Sheets via URL-embedded queries. The attackers concealed obfuscated payload code within a sheet by rendering text in white on a white background and positioning the rows thousands of lines below the visible area. All requests originate from the victim's browser to docs.google.com, appearing as normal activity within a regular browsing session.
The campaign's initial lure consisted of a fabricated leaked vulnerability report describing a non-existent API flaw. This fake report was distributed through Telegram, the cybercrime forum DarkForums, and various paste sites. The SwapZone variant promised approximately 38% higher payouts, while the SimpleSwap version offered a 25% loyalty bonus allegedly triggered by a validation gap in the loyalty endpoint.
Talos identified 49 bitcoin addresses associated with the campaign, with 30 of them appearing repeatedly across most deobfuscated samples collected between April and the end of June. Payments reached 24 of these addresses, totaling 0.159 bitcoin—valued at approximately $10,000 in early August. The funds subsequently moved through 30 additional wallets and then through transactions involving more than 3,000 addresses, consistent with cryptocurrency mixing operations. Since Talos could not recover samples from before April, the actual total is likely considerably higher.
Remediation efforts have proven ineffective. After Talos reported the malicious documents to Google and both targeted sites in April, the campaign resumed on a new sheet within a week. When paste.sh began automatically detecting the initial-stage script in July, the operators simply migrated that script into a Google Doc. Despite being reported again, the Google documents remained active as of August 11.
WebDAV-Based Loader and Malware Delivery
The second campaign likely originates from a compromised website where a malicious Cloudflare Worker injects ClearFake JavaScript. This code is stored within a BNB Smart Chain smart contract and retrieved during page load, employing a technique known as EtherHiding that allows operators to update the payload without modifying the underlying website. On Windows systems, the code displays a counterfeit Google CAPTCHA and instructs users to open the Run dialog, paste a command, and press Enter.
The pasted command opens a WebDAV path on a randomized subdomain and executes a disguised DLL through rundll32 using a function ordinal. Talos initiated investigation into this campaign after observing the same WebDAV execution pattern at a Ukrainian government organization in April. The researchers assess with moderate confidence that the attacks were not specifically targeted at any particular organization. The threat actor behind the "verification.google" activity is tracked as UAT-10820.
Both attack variants ultimately deliver Amatera, an infostealer. The configuration found in the verification.google branch contained more than 400 collection entries targeting browsers, extensions, messaging applications including Telegram, Signal and WhatsApp, password managers such as KeePass, Bitwarden and 1Password, over 100 desktop wallet locations, authenticator applications, and VPN clients. Four file grabber rules systematically search the desktop, downloads, documents, and recent items folders for private keys, wallet backups, API tokens, and certificate files.
Divergent Payload Delivery Paths
Following initial infection, the attack branches into two distinct paths. One variant sideloads a malicious NativeAOT library through a legitimate signed Google Chrome component. This library subsequently loads ZigCryptoStealer, a clipboard hijacker developed in Zig that retrieves its command and control domain from a second BNB Smart Chain contract. The stealer also deploys a legitimate but vulnerable signed driver that it exploits to terminate security software from kernel mode. A separate task executes a Go reverse TCP proxy in memory.
The alternative branch executes PowerShell code that examines volume serial numbers, system uptime, timing characteristics, processor count, memory capacity, and video adapter names to detect sandbox environments. It generates decoy traffic to GitHub, npm, PyPI, Docker Hub, and NuGet before installing a renamed version of the NetSupport Manager remote access tool. This tool is configured to conceal its interface and communicate with a gateway every 60 seconds. The gateway resolved to an address in Russia, which Talos cited when assessing with moderate confidence that a Russian actor orchestrated the "verification.google" attacks.
The ZigCryptoStealer smart contract provides insight into the campaign's scale. Deployed on March 16, its operator modified the stored domain 39 times through July 26, cycling through six different domains during July alone. Cisco Umbrella recorded queries for the most recent domain from 98 countries, with the highest concentrations in the United States, Indonesia, Brazil, India, and Egypt.
Talos emphasized the broader implications of these campaigns: "While this campaign doesn't pose a specific threat to most organizations, the approaches that the actors here are using do," the researchers wrote, highlighting potential supply-chain attacks targeting e-commerce platforms and other customer-facing systems. The team recommends implementing strict browser management policies, restricting browser extension installation by user role, and monitoring for requests to docs.google.com originating from processes and sessions showing no other Google Docs activity.


