Attackers have been stealing Bitcoin from crypto traders since October 2025 by hiding malicious code in a public Google spreadsheet, Cisco Talos researchers said. The code, written in white text on a white background, swaps deposit addresses on trading sites, and the campaign returned about a week after Google removed the first spreadsheet.
Crypto theft campaign exploits trusted Google services
A crypto theft operation targeting cryptocurrency traders has been running since October 2025, according to Cisco’s Talos threat intelligence team. Rather than relying on an obviously malicious website or suspicious server, the attackers stored key parts of their malicious code inside a publicly accessible Google spreadsheet.
The campaign begins with a lure designed to appeal to cryptocurrency traders. Victims encounter a fake security report claiming that two currency-swap platforms contain vulnerabilities that can be exploited for bonuses of 25% or more.
The offer is deliberately constructed to encourage users to participate in what appears to be an opportunity to exploit a technical flaw. Talos found the lure circulating across Telegram, criminal forums and text-sharing websites.
Users are then instructed to paste JavaScript into the Chrome address bar or incorporate it into a legitimate browser extension so the code executes whenever they return to the browser.
The initial script, however, is not the main payload. Instead, it retrieves additional code from a publicly available Google spreadsheet using a Google feature that dates back to 2008. The attackers reportedly concealed the malicious material by displaying it as white text against a white background.
That arrangement allows the operation to blend into traffic to a service that organizations commonly permit through their security systems.
“Almost every organization on earth allows traffic to Google Docs,” said Jan Heijdra, Field CTO Security at Cisco Benelux.
“So, if you can keep your attack code in a spreadsheet, you get free, reliable hosting that nobody blocks and nobody questions.”
The approach effectively removes some of the conventional warning signs associated with malicious infrastructure. There is no unusual domain for defenders to immediately flag and no dedicated server necessarily associated with the initial request.
How the crypto theft skimmer redirects funds
Once activated, the malicious code functions as a cryptocurrency skimmer.
Talos said the malware can modify the deposit address displayed on a trading website and replace an address copied by the victim. It can also insert a convincing fake bonus into the page, making the fraudulent transaction appear legitimate.
The researchers traced 49 Bitcoin addresses associated with the operation. Of those, 24 received victim funds worth at least approximately $10,000.
The stolen funds were subsequently moved through more than 3,000 additional Bitcoin addresses, a pattern that researchers identified as part of the laundering process.
The actual amount stolen could be higher. Talos said it was unable to recover samples from the earliest stage of the campaign, limiting its ability to determine the full financial impact.
The campaign also demonstrated how quickly attackers could rebuild their infrastructure after disruption.
After Talos shared its findings with Google and the affected cryptocurrency platforms in April, the lure and control documents were removed. About a week later, however, the campaign returned using a new spreadsheet.
Talos said later versions remained active into August despite being repeatedly reported.
That persistence highlights a central problem with the crypto theft campaign: removing one malicious document does not necessarily eliminate the underlying operation. Attackers can move their payload to another trusted service or document while retaining much of the same delivery mechanism.
Second campaign targets crypto wallets and credentials
Talos also documented a separate campaign that began in April 2026 after detecting unusual activity involving a Ukrainian government organization.
The researchers assessed with moderate confidence that the activity formed part of a wider cryptocurrency and credential theft operation rather than being specifically directed at the Ukrainian organization.
This campaign used a different trusted infrastructure technique.
Malicious code placed on a compromised website, through an infection chain associated with ClearFake, obtained further instructions from a public blockchain. Using blockchain infrastructure in this way gives attackers another platform that can be difficult to remove or disrupt.
Victims were subsequently presented with a fake Google CAPTCHA. Instead of simply clicking a checkbox to demonstrate that they were human, they were instructed to copy and execute a command on Windows.
That action installed Amatera, an information-stealing malware capable of harvesting browser information, messaging applications, more than 100 cryptocurrency wallets, password managers and files containing private keys.
The malware could also disable security software, use infected computers as relays for attacker traffic and install a concealed copy of a commercial remote-support application.
Talos found that the command-and-control server for the activity was hosted on an IP address in Russia. Based on that evidence, the researchers assessed with moderate confidence that a Russian threat actor operated this portion of the campaign.
The second operation demonstrates how crypto theft can extend beyond a direct attempt to access a wallet. By compromising browsers, credentials, private-key files and password managers, attackers can potentially obtain several forms of information that can later be used to access cryptocurrency and other digital assets.
Cisco warns against trusting familiar destinations
The two campaigns share a broader lesson for organizations: legitimate services can become part of malicious delivery infrastructure.
Rather than asking only whether a destination is trusted, security teams need to examine which application is making a request and whether that activity makes sense.
“The lesson isn’t to distrust Google,” Heijdra said. “It’s that ‘the destination is trusted’ has stopped being a useful signal. You need to ask which application is making the request and whether that makes any sense.”
For organizations, Talos recommends treating browsers as part of the security perimeter. Companies should control which browser extensions employees can install and monitor unusual requests to cloud collaboration services from applications or browser sessions that would not normally need access to them.
Security teams should also examine third-party components operating on customer-facing websites for unexpected or suspicious activity.
User awareness remains another line of defense.
Heijdra said organizations should make one rule particularly clear in security training: legitimate services will not ask users to copy a command and execute it as proof that they are human.
The warning is relevant beyond cryptocurrency. Although the first campaign specifically targeted crypto traders and the second harvested cryptocurrency wallets alongside other sensitive information, the underlying techniques can potentially be adapted to other forms of credential and data theft.
Talos said both investigations include detection guidance and technical indicators that security teams can use to identify related activity.