'CrashFix' Scam Crashes Browsers, Delivers Malware
ID: 6dc2b8ca-e0ce-57ca-90e5-8c4a983b5793
STIX ID: report--6dc2b8ca-e0ce-57ca-90e5-8c4a983b5793
Feed Name: Dark Reading
Huntress researchers uncovered a sophisticated campaign dubbed "CrashFix" in which a malicious Chrome extension (NexShield) masquerading as a legitimate ad blocker intentionally crashes victims' browsers and prompts a fake repair that executes a PowerShell payload contacting a C2. The actor, attributed to 'KongTuke', prioritizes domain-joined corporate systems where it deploys ModeloRAT — a Python-based remote access Trojan that gathers system and network reconnaissance, uses RC4-encrypted C2, maintains persistence via Windows Registry modifications, and employs anti-analysis techniques; Huntress published IOCs and recommends monitoring for suspicious extensions, unusual Run key entries, and hidden PowerShell processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
