Tag: ModeloRAT

Fake ad blocker extension crashes the browser for ClickFix attacks
News

Fake ad blocker extension crashes the browser for ClickFix attacks

NexShield is a phony ad-blocking Chrome and Edge extension used in a malvertising campaign that purposefully crashes the browser in advance of ClickFix attacks. The attacks, which were discovered earlier this month, resulted in the deployment of ModeloRAT, a new Python-based remote access tool used in business settings. Raymond Hill, the creator of the authentic uBlock Origin ad blocker with over 14 million users, marketed the NexShield extension, which was taken down from the Chrome Web Store, as a high-performance, lightweight, privacy-focused ad blocker. NexShield causes a denial-of-service (DoS) problem in the browser by repeatedly establishing "chrome.runtime" port connections and depleting its memory resources according to researchers read more about Fake ad blocker extensi...
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures
News

CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures

Cybersecurity researchers have revealed information about an ongoing campaign known as KongTuke, which used a malicious Google Chrome extension disguising itself as an ad blocker to purposefully crash the web browser and trick victims into executing arbitrary commands using ClickFix-like lures in order to deliver a previously undiscovered remote access trojan (RAT) known as ModeloRAT. Huntress has given this new ClickFix escalation the code name CrashFix. KongTuke is a traffic distribution system (TDS) that is known to profile victim hosts before rerouting them to a payload delivery site that infects their systems. It is also tracked as 404 TDS, Chaya_002, LandUpdate808, and TAG-124. Other threat actors, such as ransomware gangs, are subsequently granted access to these infected si...