Fake ad blocker extension crashes the browser for ClickFix attacks
NexShield is a phony ad-blocking Chrome and Edge extension used in a malvertising campaign that purposefully crashes the browser in advance of ClickFix attacks.
The attacks, which were discovered earlier this month, resulted in the deployment of ModeloRAT, a new Python-based remote access tool used in business settings.
Raymond Hill, the creator of the authentic uBlock Origin ad blocker with over 14 million users, marketed the NexShield extension, which was taken down from the Chrome Web Store, as a high-performance, lightweight, privacy-focused ad blocker.
NexShield causes a denial-of-service (DoS) problem in the browser by repeatedly establishing "chrome.runtime" port connections and depleting its memory resources according to researchers read more about Fake ad blocker extensi...


