Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim’s browser session.
First seen on blog.talosintelligence.com
Jump to article: blog.talosintelligence.com/clickfix-moves-into-the-browser/
![]()

