Threat Actors Abuse Browser Extensions to Deliver Fake Warning Messages
ID: e245dbb2-99aa-579e-b94b-84fb8fcac5d8
STIX ID: report--e245dbb2-99aa-579e-b94b-84fb8fcac5d8
Feed Name: GBHackers
Huntress researchers describe the CrashFix campaign where the KongTuke group published a malicious uBlock Origin Lite clone (NexShield) in the Chrome Web Store that triggers a browser crash via resource exhaustion, social-engineers victims into running a clipboard PowerShell command, and deploys ModeloRAT — a Python remote access trojan with RC4-encrypted C2, persistence via Run registry keys, and configurable beaconing. The report includes technical details of the extension code differences, delayed execution, misuse of finger.exe to fetch payloads, C2 IPs and domains, multiple IOCs (file hashes, extension ID, URLs), and detection/mitigation recommendations for enterprises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
