Google, SimpleSwap and SwapZone: Hackers Abuse Google Sheets as C2 in ClickFix Attacks to Steal Cryptocurrency

Google, SimpleSwap and SwapZone: Hackers Abuse Google Sheets as C2 in ClickFix Attacks to Steal Cryptocurrency

Cybercriminals Exploit Google Sheets as Covert C2 in Cryptocurrency Theft Campaign

A sophisticated cryptocurrency-stealing operation is leveraging Google Sheets and the Google Visualization API as a command-and-control (C2) channel, delivering malicious JavaScript directly into victims’ browsers. Discovered by Cisco Talos, the campaign represents an evolution of ClickFix social engineering, bypassing traditional malware installation by tricking users into executing code within Chrome.

How the Attack Works

The scheme targets cryptocurrency enthusiasts, developers, and cybersecurity professionals with a fake "API Logic Flaw" vulnerability report, promising inflated returns (e.g., 38% higher payouts on SwapZone or a 25% "loyalty bonus" on SimpleSwap). Victims are lured via Telegram channels, dark web forums, and Pastebin comments to run obfuscated JavaScript either by pasting it into Chrome’s address bar or installing it via the Tampermonkey browser extension.

Once executed, the script retrieves malicious payloads from Google Sheets, where attackers hide code in white-on-white text and deep spreadsheet rows to evade detection. The malware then intercepts cryptocurrency transactions, replacing deposit addresses with attacker-controlled wallets. It also employs clipboard hijacking, swapping copied wallet addresses to divert funds even if users manually verify them.

Technical Sophistication & Evasion Tactics

  • Google Sheets C2 Abuse: The campaign exploits the Google Visualization API (introduced in 2008) to fetch payloads from public spreadsheets, blending malicious traffic with legitimate Google HTTPS requests.
  • Browser-Based Persistence: Tampermonkey scripts auto-load on targeted sites, enabling long-term compromise without traditional malware.
  • UI Manipulation: The malware alters transaction pages, displaying fake "bonus" prompts to mask address swaps.
  • API Interception: Overrides the browser’s fetch API to modify responses, ensuring victims see attacker-controlled wallets.

Impact & Financial Losses

Cisco Talos identified 49 Bitcoin wallet addresses linked to the campaign, with 24 receiving ~0.159 BTC (~$10,000 at August 2026 valuations). Stolen funds were laundered through 3,000+ addresses, likely via mixing services to obscure trails.

Broader Implications

While targeting individuals, the techniques trusted-service abuse, browser injection, and API manipulation could be adapted for e-commerce, SaaS, or supply-chain attacks. The campaign highlights risks of unmanaged browser extensions and the need to monitor unexpected Google Visualization API traffic (e.g., docs.google.com/spreadsheets/…/gviz/tq).

Source: https://gbhackers.com/google-sheets-c2-abuse/

SimpleSwap cybersecurity rating report: https://www.rankiteo.com/company/simpleswap

Swapzone cybersecurity rating report: https://www.rankiteo.com/company/swapzone

Google Cloud Security cybersecurity rating report: https://www.rankiteo.com/company/googlecloudsecurity

"id": "SIMSWAGOO1788942524",
"linkid": "simpleswap, swapzone, googlecloudsecurity",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Cryptocurrency, Cybersecurity',
                        'name': 'Cryptocurrency enthusiasts, developers, and '
                                'cybersecurity professionals',
                        'type': 'Individuals'},
                       {'industry': 'FinTech',
                        'name': 'SwapZone',
                        'type': 'Cryptocurrency Exchange'},
                       {'industry': 'FinTech',
                        'name': 'SimpleSwap',
                        'type': 'Cryptocurrency Exchange'}],
 'attack_vector': ['Social Engineering (ClickFix)',
                   'Malicious JavaScript Execution',
                   'Browser Extension (Tampermonkey)'],
 'data_breach': {'data_exfiltration': 'Cryptocurrency funds diverted to '
                                      'attacker-controlled wallets',
                 'sensitivity_of_data': 'High (financial)',
                 'type_of_data_compromised': 'Cryptocurrency wallet addresses, '
                                             'transaction details'},
 'description': 'A sophisticated cryptocurrency-stealing operation is '
                'leveraging Google Sheets and the Google Visualization API as '
                'a command-and-control (C2) channel, delivering malicious '
                'JavaScript directly into victims’ browsers. The campaign, '
                'discovered by Cisco Talos, represents an evolution of '
                'ClickFix social engineering, bypassing traditional malware '
                'installation by tricking users into executing code within '
                'Chrome.',
 'impact': {'data_compromised': 'Cryptocurrency wallet addresses, transaction '
                                'details',
            'financial_loss': '~$10,000 (0.159 BTC as of August 2026)',
            'operational_impact': 'Interception and diversion of '
                                  'cryptocurrency transactions',
            'payment_information_risk': 'High (cryptocurrency wallet '
                                        'addresses)',
            'systems_affected': ['Victim browsers (Chrome)',
                                 'Cryptocurrency exchange platforms (SwapZone, '
                                 'SimpleSwap)']},
 'initial_access_broker': {'backdoors_established': 'Malicious JavaScript via '
                                                    'Tampermonkey',
                           'entry_point': ['Telegram channels',
                                           'Dark web forums',
                                           'Pastebin comments'],
                           'high_value_targets': ['Cryptocurrency enthusiasts',
                                                  'Developers',
                                                  'Cybersecurity '
                                                  'professionals']},
 'lessons_learned': 'Risks of unmanaged browser extensions, need to monitor '
                    'unexpected Google Visualization API traffic, and '
                    'vulnerabilities in trusted-service abuse (e.g., Google '
                    'Sheets).',
 'motivation': 'Financial Gain',
 'post_incident_analysis': {'corrective_actions': ['Enhanced monitoring of '
                                                   'Google Visualization API '
                                                   'traffic',
                                                   'User education on browser '
                                                   'extension risks',
                                                   'Transaction verification '
                                                   'for cryptocurrency '
                                                   'platforms'],
                            'root_causes': ['Exploitation of Google Sheets and '
                                            'Google Visualization API as C2',
                                            'Social engineering (fake '
                                            'vulnerability reports)',
                                            'Browser-based persistence via '
                                            'Tampermonkey',
                                            'Clipboard hijacking and fetch API '
                                            'interception']},
 'recommendations': ['Monitor for unexpected Google Visualization API traffic '
                     '(e.g., `docs.google.com/spreadsheets/…/gviz/tq`).',
                     'Educate users on the risks of executing untrusted '
                     'JavaScript or installing browser extensions from '
                     'unverified sources.',
                     'Implement transaction verification mechanisms to detect '
                     'wallet address swaps.'],
 'references': [{'source': 'Cisco Talos'}],
 'response': {'enhanced_monitoring': 'Monitoring for unexpected Google '
                                     'Visualization API traffic',
              'third_party_assistance': 'Cisco Talos (discovery and analysis)'},
 'title': 'Cybercriminals Exploit Google Sheets as Covert C2 in Cryptocurrency '
          'Theft Campaign',
 'type': 'Cryptocurrency Theft',
 'vulnerability_exploited': ['Google Visualization API',
                             'Browser Fetch API Override',
                             'Clipboard Hijacking']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.