logo

ClickFix to CrashFix: KongTuke Used Fake Chrome Ad Blocker to Install ModeloRAT

ID: 6026f5b5-4fc9-5348-9784-436138031c21

STIX ID: report--6026f5b5-4fc9-5348-9784-436138031c21

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive Summary:** Huntress uncovered a KongTuke campaign that distributes a fake Chrome ad-blocker named NexShield which deliberately crashes browsers (CrashFix), then prompts users to run a command that installs the ModeloRAT backdoor; ModeloRAT exfiltrates data and credentials, uses evasion/fingerprinting to avoid detection, and focuses on corporate targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.