Dissecting CrashFix: KongTuke's New Toy
ID: 39c8158c-7cc4-52fa-9fdf-d32445284afa
STIX ID: report--39c8158c-7cc4-52fa-9fdf-d32445284afa
Feed Name: Huntress Blog
KongTuke's CrashFix campaign distributes a malicious Chrome extension (NexShield, impersonating uBlock Origin Lite) that deliberately exhausts browser resources to trigger a fake 'CrashFix' prompt which tricks users into executing clipboard-pasted commands; home systems currently receive a test payload while domain-joined machines are served ModeloRAT (a Python RAT with RC4-encrypted HTTP C2, persistence via Run registry entries, and support for executables/DLLs), alongside a layered .NET GateKeeper payload using AES+XOR encryption, weekly DGA domains, AMSI bypass, and extensive anti-analysis/fingerprinting; the report provides actionable IOCs (extension ID, hashes, C2 IPs, URLs) and detection advice such as monitoring for suspicious extensions, LOLBin usage (finger.exe), unexpected pythonw.exe/powershell activity, Run-key persistence, and beaconing to listed C2 infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
