Connect with us

NEWS

ClickFix Now Runs Inside Chrome and WebDAV Shares

Cisco Talos found ClickFix campaigns that paste JavaScript into Chrome and pull DLLs over WebDAV, using Google Sheets and blockchain contracts as command channels.

Published

on

Cisco Talos detailed two ClickFix campaigns on Sept. 8 that paste code into Chrome or a WebDAV share instead of a PowerShell prompt. One campaign never touches Windows. The other starts with a fake Google CAPTCHA and ends in the Amatera infostealer.

The in-browser branch paid 0.159 bitcoin, about $10,000 in early August. The same plumbing, Chrome, Google Sheets, and WebDAV, is what Talos says companies should treat as the live problem.

What ClickFix Does Inside Chrome

ClickFix grew up in 2024 as a fake error or CAPTCHA that told the visitor to paste a command into the Windows Run dialog or a Mac terminal. The user ran the code, so download warnings and mail filters never saw a file. Microsoft Threat Intelligence first recorded that pattern between March and June 2024 in Storm-1607 mail, and it has watched ClickFix hit thousands of devices globally every day.

Talos’s first campaign drops that OS step. The lure is a fake leaked vulnerability report that describes an API flaw that does not exist. It was seeded on Telegram, the cybercrime board DarkForums, and paste sites. The people it wants are the ones who think they are about to cheat a swap desk.

On SwapZone.io the pitch was roughly 38% higher payouts. A later rewrite aimed at SimpleSwap.io dangled a 25% loyalty bonus from a supposed gap in a loyalty endpoint. The “fix” is JavaScript. Early samples told the visitor to paste it into the Chrome address bar. Later ones told them to drop it into the Tampermonkey extension, which reloads the script on every visit to the targeted site.

Once it is in the browser, the code skims. It hooks Chrome’s fetch API, swaps cryptocurrency deposit addresses in server replies and in the clipboard, and paints fake “bonus” elements so the numbers on screen still add up. Windows never runs a process. Endpoint tools that watch PowerShell, rundll32, or the Run dialog have nothing to log.

In August, Cato Networks documented a related Mac lure that still needed Terminal: a fake OpenAI Codex installer on Google Sites, found through ads for “codex macos download,” that walked developers into pasting a command. Talos’s SwapZone chain is the next cut. The paste never leaves Chrome.

Google Sheets Still Serve the Skimmer

Command and control sits in the Google Visualization API, a charts feature from 2008 that will read any published Google Sheet through a query stuffed into a URL. Google’s own charts documentation says spreadsheets shared so public sheets need no login. The operators hid obfuscated payload text by coloring it white on white and shoving the rows thousands of lines down the grid.

The browser asks docs.google.com in the middle of an otherwise normal session. To a proxy, it looks like someone opened a spreadsheet.

THE SWAPZONE SKIM IN BITCOIN

  • Addresses found: Talos pulled 49 bitcoin addresses from samples it deobfuscated from April through the end of June.
  • Repeat wallets: 30 of those addresses showed up across most of the samples.
  • Paid out: 24 addresses received funds, 0.159 bitcoin in total, about $10,000 in early August.
  • Cash out: coins then moved through 30 further wallets and through transactions touching more than 3,000 addresses, consistent with mixing.

Talos could not recover samples from before April, so the haul is likely higher. The money is small next to a corporate breach. The channel is the part that travels.

Talos reported the documents to Google and to both swap sites in April. The campaign was back on a new sheet within a week. After paste.sh started auto-detecting the first-stage script in July, the operators moved that script into a Google Doc as well. Those documents were reported again and were still answering queries as of Aug. 11, 2026.

A Fake Google CAPTCHA Opens WebDAV

The second campaign starts on a hacked site. A malicious Cloudflare Worker injects ClearFake JavaScript, and that code is stored in a BNB Smart Chain smart contract and pulled at page load. Google Threat Intelligence Group describes EtherHiding as a way to keep payloads stored in blockchain contracts, readable with a free eth_call that leaves no transaction to seize. Only the wallet that owns the contract can change what every infected page serves next.

On Windows the overlay is a fake Google CAPTCHA. It tells the visitor to open the Run dialog, paste, and press Enter. The pasted command opens a WebDAV path on a randomized subdomain and launches a disguised DLL through rundll32 by function ordinal. There is no.exe sitting in Downloads. Windows is fetching a remote library with a built-in file-share protocol and a signed system binary.

That is the point of the second campaign. Defenders spent two years teaching staff not to paste PowerShell into Run. Moving the payload onto a WebDAV share and through rundll32 hits the gap that hunt teams already flag as a blind spot, because those are trusted Windows parts, not a dropped installer. Palo Alto Networks Unit 42 recorded a cousin chain in August that used pcalua.exe to open a WebDAV share through rundll32 over per-victim URLs.

Talos opened the case after seeing the same WebDAV execution pattern at a Ukrainian government organization in April. It assesses with moderate confidence that the attacks were not aimed at any one outfit. It tracks the “verification.google” cluster as UAT-10820, and it treats a gateway that resolved to Russia as a moderate-confidence sign of a Russian operator on that branch.

Amatera Then Splits the Job

Both WebDAV loaders deliver Amatera. In the verification.google branch the stealer’s config ran to more than 400 collection entries. Four file-grabber rules then sweep Desktop, Downloads, Documents, and Recent for private keys, wallet backups, API tokens, and certificate files.

WHAT AMATERA WAS SET TO COLLECT

  • Browsers and extensions: saved logins, cookies, and add-on data from the usual desktop browsers.
  • Messaging apps: Telegram, Signal, and WhatsApp among the listed targets.
  • Password managers: KeePass, Bitwarden, and 1Password sit in the same config.
  • Wallets and extras: more than 100 desktop wallet locations, plus authenticator apps and VPN clients.

Follow-on jobs then fork. One branch sideloads a malicious NativeAOT library through a signed Google Chrome component. That library loads ZigCryptoStealer, a clipboard hijacker written in Zig, pulls its command domain from a second BNB Smart Chain contract, and drops a legitimate but vulnerable signed driver that it abuses to kill security software from kernel mode. A separate task runs a Go reverse TCP proxy in memory.

Branch How it starts What it loads
ZigCryptoStealer NativeAOT library sideloaded through a signed Chrome component Clipboard hijacker, a second BNB contract for C2, a vulnerable signed driver used to stop security tools
NetSupport Manager PowerShell after sandbox checks and decoy traffic A renamed copy of the remote-access tool, interface hidden, polling a gateway every 60 seconds

The NetSupport branch is noisier on purpose, then quiet. PowerShell checks volume serial numbers, uptime, timing, processor count, memory, and video adapter names for sandbox tells. It generates decoy traffic to GitHub, npm, PyPI, Docker Hub, and NuGet, then installs the renamed remote-access tool and hides its interface.

The ZigCryptoStealer contract gives a floor on volume. It was deployed on March 16, 2026, and its operator updated the stored domain 39 times through July 26, cycling 6 domains during July alone. Cisco Umbrella recorded queries for the most recent of those domains from 98 countries, most often the United States, Indonesia, Brazil, India, and Egypt.

ClickFix Left the Run Dialog Behind

The paste-a-fix trick is no longer one move. In two years it picked up Mac Terminal, Chrome’s address bar, Tampermonkey, WebDAV, and on-chain dead drops, while the lure stayed a fake check the user is eager to pass.

HOW THE PASTE CHANGED

  1. September 2023: ClearFake starts hiding second-stage JavaScript in BNB Smart Chain contracts, the EtherHiding pattern Google later tied to UNC5142.
  2. March to June 2024: Microsoft sees ClickFix in Storm-1607 email, HTML attachments, and fake Word errors that copy a command to the clipboard.
  3. March 16, 2026: the ZigCryptoStealer contract is deployed; domain swaps continue through July 26.
  4. April 2026: Talos sees the WebDAV pattern at a Ukrainian government organization, reports the SwapZone Google documents, and watches a new sheet appear within a week.
  5. July 2026: paste.sh starts catching the first-stage script; operators move it into a Google Doc, and the ZigCryptoStealer domain rotates 6 times.
  6. August 11, 2026: the Google documents Talos reported are still live. Cato later in the month documents the fake Codex installer for Mac.
  7. Sept. 8, 2026: Talos publishes the in-browser skim and the UAT-10820 WebDAV chain together.

Microsoft’s July work on ACR Stealer, the family Amatera sits in, already described two ClickFix paths that split between WebDAV plus Python loaders and a fileless steganography chain, then stole the same browser credentials and session tokens. UAT-10820 is one more operator using that split, not the first.

The Methods Outlast the Takedowns

While this campaign doesn’t pose a specific threat to most organizations, the approaches that the actors here are using do.

Cisco Talos Threat Intelligence researchers

Talos pointed at supply-chain hits on e-commerce and other customer-facing systems. A Tampermonkey script that rewrites fetch on a checkout or swap page does not need a foothold on the laptop. A Worker that pulls its next stage from a BNB contract does not need a domain a registrar can freeze. A Sheet that answers /gviz/tq from docs.google.com does not look like malware hosting.

The shop-floor advice is narrow. Manage browsers as a fleet, restrict who can install extensions, and watch for docs.google.com calls from processes and sessions that have no other Google Docs work. None of that closes Visualization API reads on a public sheet, and none of it seizes a smart contract. The SwapZone operators were back on a new sheet inside a week of the April reports, and Umbrella was still seeing the newest ZigCryptoStealer domain from 98 countries after 39 on-chain swaps.

Harry runs CREATE MORE FLOW, an independent site, as its editor and lead writer, drawing on a decade of journalism that began in reporting and ended up in editing. His process is the same for every piece. A tip or a document comes in, he finds the primary source behind it, whether that is a regulatory filing, a transcript, a dataset he can open or a product he can test himself, and only then does the writing start. Before anything is published, each number is checked against where it came from, quotes are compared with the recording or transcript, and dates are confirmed. That routine serves a global readership across technology, business and news, science and sports, entertainment and lifestyle, travel, auto and gaming. When a mistake gets through, he corrects the article and leaves a dated note explaining the change, under a corrections policy that is published on the site. He reads his own inbox, and readers can reach him at support@createmoreflow.com with tips, documents or complaints.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending