logo

CrashFix: New ClickFix Variant Deliberately Breaks Browsers to Deploy RAT

ID: 97e8dcb9-ea9e-58e5-9d78-e7d417fc5a7c

STIX ID: report--97e8dcb9-ea9e-58e5-9d78-e7d417fc5a7c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-06

Date Updated: 2026-04-23

Author: Ddos

...
...

CrashFix is an escalation of the ClickFix social‑engineering campaign that lures users to install a fake Chrome extension (impersonating ad blockers), deliberately crashes the browser to induce a "fix" workflow, and tricks victims into running a command which abuses finger.exe to retrieve an obfuscated PowerShell loader that ultimately installs ModeloRAT — a Python-based RAT that achieves persistence via a scheduled task named "SoftwareProtection" and registry modifications. The report includes TTPs, enterprise-focused checks (domain-joined detection, anti-analysis checks), and IOCs such as IP 69.67.173.30 and a renamed ct.exe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.