Criminals are using Google Sheets to steal crypto

Most of us wouldn’t expect a Google spreadsheet to be part of a crypto theft operation. We use them for budgets and work, and a link to Google Docs generally looks less suspicious than a web address we’ve never seen before. Criminals are making use of that familiarity, storing malicious code in public spreadsheets and persuading people to run it in their own browsers.

Cisco’s threat intelligence team, Talos, has documented a scam aimed at cryptocurrency traders who think they’ve found a way to get more money out of a transaction. The supposed opportunity comes in a leaked security report. Follow its instructions and you’ll allegedly receive a bigger payout by exploiting a flaw in a trading service.

There’s no such flaw. Once the victim runs the code, it changes the deposit address on the trading page so the money goes to the attacker, while a fake bonus helps make everything look as though it’s working.

The spreadsheet supplies the code

In its investigation into the browser scam, published on 8 September, Talos describes a variation of ClickFix. These attacks persuade someone to copy and run code by giving them a reason to believe it’s necessary. Often, they’re told it will fix something that’s broken.

Here, the incentive was money. The fake report circulated through Telegram and online forums, directing people to run JavaScript in Chrome. Later versions used Tampermonkey, a legitimate browser extension that can run scripts on websites. The script supplied by the criminals fetched the malicious code from Google Sheets.

That arrangement made the activity harder to spot. A browser requesting content from Google isn’t unusual, and the extension itself has legitimate uses. The attackers even concealed the spreadsheet’s contents with white text on a white background.

Once loaded, the code changed the deposit address displayed on the trading page and the address copied by the victim. It also added a fake bonus to make the promised payout look believable. Someone could be on the genuine trading website and still be seeing payment details supplied by a criminal.

Cisco’s accompanying statement says Talos identified 49 Bitcoin addresses used in the campaign. Of those, 24 received victim funds worth roughly US$10,000 at early August valuations. Researchers believe the amount stolen could be higher because they couldn’t recover all the earlier versions.

The offer also helped explain away the odd instructions. If you believe you’re accessing a hidden trading feature, installing an extension or adding a script might seem like part of the process. You’re expecting to do something the website doesn’t normally allow, so an unusual setup becomes easier to accept.

The fake verification prompt

A second Talos investigation looked at a different use of ClickFix. Researchers found a fake Google CAPTCHA prompt on a compromised website that told Windows users to paste and execute a command to prove they were human.

Following those instructions delivered Amatera, malware designed to steal sensitive information. Talos investigated two similar infection chains with different follow-on payloads. One was instructed to deploy additional crypto-stealing malware and a traffic proxy. The other was instructed to install a hidden copy of NetSupport Manager, a commercial remote-support tool.

We’re used to verification boxes interrupting whatever we’re trying to do online. Usually, we click through them because we want to get to the page behind them. A fake prompt takes advantage of that habit, although asking someone to run a command on their computer goes well beyond anything a normal CAPTCHA requires.

The investigation began with suspicious activity at a Ukrainian government organisation. Talos believes, with moderate confidence, that it was part of a broader theft operation rather than an attack aimed specifically at that organisation. Researchers reconstructed the fake CAPTCHA sequence from a similar chain; they didn’t recover every earlier stage of the Ukrainian incident.

That matters when describing what happened. The findings support a warning about the method, but they don’t establish that every affected computer went through exactly the same steps.

What we should be looking for

These reports don’t tell us how common the attacks are in South Africa. They do describe misuse of services many of us use, which makes the behaviour worth recognising without presenting it as a confirmed local outbreak.

There’s a familiar problem here with attackers using legitimate remote-access software. Knowing that a tool comes from a recognised company doesn’t tell you who’s using it or what they intend to do. A genuine Google document gives its contents no more credibility than any other document somebody has shared with you.

Cisco’s field CTO for security in Benelux, Jan Heijdra, recommends that businesses control which browser extensions staff can install and investigate unexpected requests to cloud services. Allowing access to Google Docs makes sense for a workplace. Treating every request to it as harmless leaves room for the kind of activity Talos found.

For anyone browsing at home, a verification prompt that asks you to open Windows Run or Terminal and paste a command is a reason to leave the page. A document promising a secret trading bonus should raise questions too, regardless of where it’s hosted.

We’ve spent years being told to check links before clicking them. That advice still helps, but in this scam the Google address was real and the trading page could be genuine. The request to run somebody else’s code deserved much more attention than either.

Zeen Social Icons