logo

Fake ad blocker extension crashes the browser for ClickFix attacks

ID: 46c49f1e-291f-58c7-b11f-2fb71930f3f7

STIX ID: report--46c49f1e-291f-58c7-b11f-2fb71930f3f7

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malvertising campaign distributed a malicious browser extension named NexShield that forces Chrome/Edge to crash (CrashFix) and then displays deceptive prompts instructing users to paste and run commands; those commands launch an obfuscated PowerShell chain that downloads a Python-based RAT called ModeloRAT. Huntress attributes the activity to KongTuke, notes a 60-minute execution delay to evade detection, and warns the actor is increasingly targeting enterprise/domain-joined hosts where ModeloRAT can perform reconnaissance, execute commands, persist, and update itself.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.