ModeloRAT is a remote access trojan associated with a campaign that distributes a counterfeit ad-blocker extension.
ModeloRAT is a remote access trojan associated with a campaign that distributes a counterfeit ad-blocker extension. The operation, linked to ClickFix attacks, leverages the fake extension to crash browsers and establish attacker control over infected hosts. This underscores the risk of malicious browser extensions being used as delivery and persistence vectors in contemporary malware campaigns.
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
The Mistic malware, a newly identified Windows backdoor, has been active since April 2026, utilizing DLL sideloading to infiltrate enterprise environments. It exploits a legitimate executable, MpExtMs.exe, to load a…
The KongTuke group is actively deploying modeloRAT malware through compromised WordPress sites, utilizing fake CAPTCHA lures for initial access. This campaign continues alongside their newer CrashFix technique, posing a…
A malicious campaign named CrashFix has been identified, utilizing a fake ad-blocking browser extension called NexShield to crash users' browsers. This tactic is employed to facilitate ClickFix attacks, delivering a new…
Security researchers have identified a malicious browser extension named NexShield that masquerades as an ad blocker for Chrome and Edge. Upon installation, it intentionally crashes the browser, misleading users into…
The QuickLens Chrome extension, which allowed users to perform Google Lens searches, was compromised on February 17, 2026, with the release of version 5.8 that introduced malware capable of stealing cryptocurrency…