$ techbeacon▋
Malware

Hackers Exploit Google Sheets as Stealthy C2 Platform in New Crypto‑Theft Campaign

Hackers Exploit Google Sheets as Stealthy C2 Platform in New Crypto‑Theft Campaign

Security researchers have uncovered a fresh cryptocurrency‑theft operation that leverages Google Sheets and the Google Visualization API as a covert command‑and‑control (C2) channel. By embedding obfuscated JavaScript into a legitimate Google service, the attackers can deliver malicious code directly to victims' browsers without raising the typical alarms associated with traditional malware distribution.

The technique involves creating a publicly accessible Google Sheet that contains encoded instructions for compromised browsers. The sheet is accessed through the Visualization API, which returns data in a format that can be parsed and executed by a hidden script running on the victim’s machine. Because the traffic originates from Google’s own infrastructure, it blends in with normal web activity and can evade many network‑based detection tools.

Analysts identified the campaign as an evolution of the ClickFix malware family, a set of tools historically associated with social‑engineering attacks that trick users into installing malicious browser extensions or scripts. In this iteration, the malicious payload is delivered entirely through the browser session, eliminating the need for a separate downloader or installer. Once the obfuscated JavaScript runs, it hijacks the victim’s cryptocurrency wallets or injects mining scripts, siphoning funds or generating illicit earnings.

Researchers noted that the use of a cloud‑based spreadsheet as a C2 server is not entirely new, but the integration with the Visualization API adds a layer of sophistication. The API returns data in JSON‑like structures, which can be easily parsed by JavaScript, allowing the attackers to issue dynamic commands, update payloads, or retrieve stolen data without altering the underlying sheet’s visible content.

The discovery highlights a growing trend where threat actors repurpose widely trusted services to mask malicious activity. By piggybacking on Google’s infrastructure, the attackers benefit from the platform’s high availability, built‑in redundancy, and the perception of legitimacy that often shields such traffic from scrutiny by both corporate firewalls and endpoint security solutions.

Experts recommend that organizations reinforce browser security hygiene, including the use of script‑blocking extensions, strict content security policies, and regular monitoring of outbound traffic for anomalous calls to cloud APIs. As attackers continue to innovate with “living off the land” tactics, vigilance and layered defenses remain essential to protect users from covert crypto‑theft schemes.

Source: GBHackers
Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related