CrashFix Chrome Extension Delivers ModeloRAT Payload
⚠️ Researchers disclosed an active campaign, tracked as KongTuke and codenamed CrashFix, that used a malicious Chrome extension posing as an ad blocker to deliberately crash browsers and coerce victims into running commands. The fake add-on, “NexShield – Advanced Web Guardian,” impersonated uBlock Origin Lite, garnered 5,000+ installs, and implements delayed execution, DoS crash loops, and anti-analysis controls. The lure prompts users to paste a pre-copied command into the Windows Run dialog that abuses finger.exe to fetch a PowerShell chain, ultimately delivering the previously undocumented ModeloRAT. Huntress warns the technique weaponizes user frustration to create a persistent, self-sustaining infection loop that can hand victims off to other threat actors.
