Bleepingcomputer
CrashFix Campaign Delivers ModeloRAT via Malicious Chrome Extension
First seen 21 Jan 2026, 06:39 UTC
•

•86% similarity
•33.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A malicious campaign named CrashFix has been identified, utilizing a fake ad-blocking browser extension called NexShield to crash users' browsers. This tactic is employed to facilitate ClickFix attacks, delivering a new Python-based remote access tool known as ModeloRAT, primarily targeting corporate environments. The NexShield extension has since been removed from the Chrome Web Store.
ThreatCluster AI
How this analysis works