Bleepingcomputer CrashFix Campaign Delivers ModeloRAT via Malicious Chrome Extension
Article Content
Browse articles
A malicious campaign named CrashFix has been identified, utilizing a fake ad-blocking browser extension called NexShield to crash users' browsers. This tactic is employed to facilitate ClickFix attacks, delivering a new Python-based remote access tool known as ModeloRAT, primarily targeting corporate environments. The NexShield extension has since been removed from the Chrome Web Store.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (3)
Following this threat?
Track KongTuke and ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts Rapid7's Q2 2026 Threat Landscape Report reveals a significant increase in vulnerability disclosures, with high and critical vulnerabilities doubling to 8,539. Newly exploited vulnerabilities surged by 40%, with 62% requiring no user interaction to exploit. The report highlights that attackers are leveraging…