logo

CrashFix – Hackers Using Malicious Extensions to Display Fake Browser Warnings

ID: f7cc0e47-8369-51fe-b37a-b2045c5e5268

STIX ID: report--f7cc0e47-8369-51fe-b37a-b2045c5e5268

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Cybersecurity researchers uncovered the CrashFix campaign, where a malicious Chrome extension (NexShield) intentionally crashes browsers by exhausting runtime ports, then prompts victims to run a clipboard PowerShell command that installs additional malware (including ModeloRAT); the operation is attributed to KongTuke and preferentially targets corporate, domain-joined machines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.