logo

Dissecting CrashFix: KongTuke's New Toy

ID: 39c8158c-7cc4-52fa-9fdf-d32445284afa

STIX ID: report--39c8158c-7cc4-52fa-9fdf-d32445284afa

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-01-16

Date Updated: 2026-04-28

...
...

KongTuke's CrashFix campaign distributes a malicious Chrome extension (NexShield, impersonating uBlock Origin Lite) that deliberately exhausts browser resources to trigger a fake 'CrashFix' prompt which tricks users into executing clipboard-pasted commands; home systems currently receive a test payload while domain-joined machines are served ModeloRAT (a Python RAT with RC4-encrypted HTTP C2, persistence via Run registry entries, and support for executables/DLLs), alongside a layered .NET GateKeeper payload using AES+XOR encryption, weekly DGA domains, AMSI bypass, and extensive anti-analysis/fingerprinting; the report provides actionable IOCs (extension ID, hashes, C2 IPs, URLs) and detection advice such as monitoring for suspicious extensions, LOLBin usage (finger.exe), unexpected pythonw.exe/powershell activity, Run-key persistence, and beaconing to listed C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.