CrashFix – Hackers Using Malicious Extensions to Display Fake Browser Warnings
ID: f7cc0e47-8369-51fe-b37a-b2045c5e5268
STIX ID: report--f7cc0e47-8369-51fe-b37a-b2045c5e5268
Feed Name: cybersecurityNews.com
Threat Score
Cybersecurity researchers uncovered the CrashFix campaign, where a malicious Chrome extension (NexShield) intentionally crashes browsers by exhausting runtime ports, then prompts victims to run a clipboard PowerShell command that installs additional malware (including ModeloRAT); the operation is attributed to KongTuke and preferentially targets corporate, domain-joined machines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
