logo

Threat Actors Abuse Browser Extensions to Deliver Fake Warning Messages

ID: e245dbb2-99aa-579e-b94b-84fb8fcac5d8

STIX ID: report--e245dbb2-99aa-579e-b94b-84fb8fcac5d8

Feed Name: GBHackers

Threat Score
76/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Huntress researchers describe the CrashFix campaign where the KongTuke group published a malicious uBlock Origin Lite clone (NexShield) in the Chrome Web Store that triggers a browser crash via resource exhaustion, social-engineers victims into running a clipboard PowerShell command, and deploys ModeloRAT — a Python remote access trojan with RC4-encrypted C2, persistence via Run registry keys, and configurable beaconing. The report includes technical details of the extension code differences, delayed execution, misuse of finger.exe to fetch payloads, C2 IPs and domains, multiple IOCs (file hashes, extension ID, URLs), and detection/mitigation recommendations for enterprises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.