Fake extension crashes browsers to trick users into infecting themselves
ID: 5426a837-100d-5848-8c0a-8c86d1a849a9
STIX ID: report--5426a837-100d-5848-8c0a-8c86d1a849a9
Feed Name: Malwarebytes Blog
Researchers uncovered a Chrome Web Store impostor extension that deliberately crashes the browser via a resource-exhausting loop, then shows a fake recovery instruction prompting users to paste and execute a clipboard command; following that social-engineering step the attacker deploys malware, fingerprinting domain membership to install a Python RAT (ModeloRAT) on corporate devices while delivering an unknown/test payload on others. The extension phones home to a misspelled domain (nexsnield.com), waits 60 minutes before triggering to evade quick detection, and was removed from the store but may resurface; recommended mitigations include avoiding executing copied commands, installing only trusted extensions, and using up-to-date anti-malware/browser protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
