Fake “API Exploit” Lures Users Into Self-Hacking

Cisco Talos · High sophistication
Last updated September 8, 2026

Cisco Talos reports a real cryptocurrency-theft campaign where criminals trick people into pasting JavaScript into their browser or installing it via the Tampermonkey extension. The lure pretends to be a leaked vulnerability report for crypto swap sites, but the “exploit” is fake and instead injects a web-skimming script that swaps deposit addresses to steal funds. The attackers also abuse Google Sheets/Docs (via the Google Visualization API) for command-and-control, hiding activity inside normal-looking Google traffic.

Key findings

  • Attackers used a ClickFix-style trick to get victims to run attacker-supplied JavaScript in their own browser session (not on the operating system).
  • The lure was a fake “leaked vulnerability report” (file name “API Logic Flaw”) promising higher payouts/bonuses on crypto swap services to entice greed.
  • Lures were distributed through Telegram, DarkForums, and paste/text-sharing sites; earlier versions also used email.
  • Malicious code was staged in publicly published Google Sheets and retrieved via the Google Visualization API for browser-based command-and-control.
  • The injected script behaves like a web skimmer: it hooks browser web requests and replaces crypto deposit addresses in both page content and clipboard.

Who’s being targeted

  • Commonly targeted roles: All employees (security awareness baseline), Developers/engineers, Finance teams handling payments/crypto, Employees who use browser extensions heavily.
  • Affected industries: Cryptocurrency trading and exchange services, Online financial services, Individual consumers (crypto traders).
  • Attack channels: website, telegram.
  • Impersonated: Independent security researcher / leaked vulnerability report author, Scammer-run Telegram ‘exploit’ channel / “Updated Docs” poster.

Awareness takeaways

  • Treat any request to paste code into a browser (or run code to get a ‘bonus’) as a scam and report it.
  • Be cautious of ‘leaked security reports’ or ‘updated docs’ shared via Telegram/forums, especially those promising easy money.
  • Don’t assume Google-hosted links are safe; attackers can abuse trusted services (Docs/Sheets) to deliver harmful content.
  • For crypto-related payments, verify deposit addresses and watch for unexpected address changes or clipboard tampering.

Red flags to watch for

  • Instructions to run code directly in the browser address bar using “javascript:”
  • Promise of unusually high returns (e.g., higher payouts/bonuses) from a supposed ‘exploit’
  • Links routed through public paste sites and Google Docs instead of official vendor channels
  • Being instructed to install a browser extension to ‘activate’ a financial bonus
  • Script injection/pasting steps coming from Telegram/dark forums rather than the legitimate service
  • Claims the victim should limit transactions (behavior-manipulation guidance)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine a Telegram post titled “API Logic Flaw” promising a 25% crypto bonus if you run a secret browser exploit. The trick? They tell you to paste JavaScript into Chrome’s address bar, or install Tampermonkey and add a script from paste.sh, to ‘activate’ the bonus on SimpleSwap.io. Behind the scenes, that script pulls more code from a Google Sheet via the Google Visualization API, then skims your browser, silently swapping crypto deposit addresses on the page and in your clipboard. Here’s the rule: if anyone tells you to paste code into your browser or install a script for extra payouts, stop immediately and report it to Security.

Similar attacks

Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
DEF CON Phish Uses Fake Coindesk VP + Google Doc

DEF CON Phish Uses Fake Coindesk VP + Google Doc

A real phishing campaign is targeting DEF CON speakers and attendees through X/Twitter messages pretending to be a Coindesk executive. Victims are sent to a Google document that attempts a “click-fix” trick to get them to paste malicious commands into a terminal or download malware. The goal is to…

August 21, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026