A cryptocurrency-stealing campaign that abuses Google Sheets and the Google Visualization API as a covert command-and-control channel, delivering obfuscated JavaScript directly into victims’ browser sessions. The operation marks a significant evolution of ClickFix social engineering: rather than persuading users to execute PowerShell commands or install malware on an operating system, attackers manipulate them into running […]
Read the original article: