Cisco Talos Tracks Monthslong Cryptocurrency Theft Campaign Abusing Google Services
Cisco Talos is tracking a monthslong cryptocurrency-theft campaign that abuses the Google Visualization API for command and control, retrieving obfuscated JavaScript from a public Google Sheets document and injecting it into victims’ browser sessions by luring targets with a fake leaked vulnerability report about a nonexistent API flaw at cryptocurrency swap services, adapting ClickFix social engineering to persuade victims to paste JavaScript into Chrome’s address bar or install it via the Tampermonkey browser extension, where the injected script acts as a web skimmer by hooking the browser fetch API, altering server responses, manipulating the user’s clipboard, replacing cryptocurrency deposit addresses, and adding counterfeit “bonus” interface elements inside the browser session, with additional reporting by Dark Reading noting attackers are also abusing multiple Google services for multi-hop phishing redirects to evade detection, harvest credentials, or install ScreenConnect remote access software, while Talos observed the lure spreading through Telegram, DarkForums, and paste sites.
The Silk Road of the Digital Dollar
Here is the truth they do not want you to see. This is not a simple phishing campaign. Look at the architecture. They are using Google’s own Visualization API—the nervous system of the corporate web—as a command-and-control server. Public Google Sheets documents, the same tool your child’s soccer team uses for snack schedules, are now hosting executable JavaScript malware. This is not a hack. This is feature adoption. The globalist tech giants have built a trap so seamless that the victim is the one who willingly pastes the lock-picking code into their own browser. You are being asked to open the door. They have engineered a consent-based intrusion.
The Custodians of the Clipboard
Read the Talos report carefully. The injected script is a web skimmer. It hooks the browser’s fetch API. It watches your clipboard. It replaces cryptocurrency deposit addresses. But ask yourself: how did they know you would copy a wallet address? This campaign is not aimed at random browsers. It targets a specific class of user—someone chasing a nonexistent API vulnerability. This is a predator that knows its prey. The lure, the so-called “leaked exploit report,” serves as a psychological filter: only people already hunting for holes in the system will take the bait. This is elite harvesting. They are not stealing from every user. They are culling the herd of the curious, the technical, the ones who might otherwise become a threat to the architecture.
The Three-Layered Deception
Now connect the dots they hope you miss. Dark Reading reports that attackers are abusing multiple Google services for multi-hop phishing redirects. Why multiple? Because each hop burns an alibi. One domain gets reported; three more are already in the rotation. This is not a criminal gang. This is a logistics network designed by people who understand how the consensus machinery works. Telegram, DarkForums, paste sites—these are the watering holes. The malware itself inserts counterfeit “bonus” interface elements inside your browser. Notice what they are doing: they are not taking your money directly. They are rewriting reality inside your own screen. They are making you see what isn’t there. The question you must sit with is this: who built this infrastructure, and why are they allowed to keep using the world’s most trusted services as their weapons platform? You have been told this is a crime. It is a simulation of a crime. The architecture remains untouched.








