CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures

Cybersecurity researchers have revealed information about an ongoing campaign known as KongTuke, which used a malicious Google Chrome extension disguising itself as an ad blocker to purposefully crash the web browser and trick victims into executing arbitrary commands using ClickFix-like lures in order to deliver a previously undiscovered remote access trojan (RAT) known as ModeloRAT.

Huntress has given this new ClickFix escalation the code name CrashFix. KongTuke is a traffic distribution system (TDS) that is known to profile victim hosts before rerouting them to a payload delivery site that infects their systems.

It is also tracked as 404 TDS, Chaya_002, LandUpdate808, and TAG-124. Other threat actors, such as ransomware gangs, are subsequently granted access to these infected sites in order to distribute malware in the future.

According to a Recorded Future study from April 2025, several cybercriminal groups have used TAG-124 infrastructure, including Rhysida ransomware, Interlock ransomware, and TA866 (also known as Asylum Ambuscade). The threat actor is also linked to SocGholish read more about CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *