Fake ad blocker extension crashes the browser for ClickFix attacks
ID: 46c49f1e-291f-58c7-b11f-2fb71930f3f7
STIX ID: report--46c49f1e-291f-58c7-b11f-2fb71930f3f7
Feed Name: Bleeping Computer
A malvertising campaign distributed a malicious browser extension named NexShield that forces Chrome/Edge to crash (CrashFix) and then displays deceptive prompts instructing users to paste and run commands; those commands launch an obfuscated PowerShell chain that downloads a Python-based RAT called ModeloRAT. Huntress attributes the activity to KongTuke, notes a 60-minute execution delay to evade detection, and warns the actor is increasingly targeting enterprise/domain-joined hosts where ModeloRAT can perform reconnaissance, execute commands, persist, and update itself.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
