CrashFix Chrome Extension Deploys ModeloRAT
A malicious browser add-on known as the CrashFix Chrome extension is at the center of a newly discovered cyber campaign that tricks users into running harmful commands. Cybersecurity researchers have attributed the ongoing activity, labeled KongTuke, to attackers distributing the extension under the guise of an ad blocker. Once installed, it deliberately crashes the Chrome browser and mimics earlier ClickFix-style tactics to manipulate users into taking specific actions.
Victims unknowingly execute remote commands, allowing threat actors to deploy a newly identified remote access trojan named ModeloRAT. The malware grants attackers covert control over targeted systems, posing significant risks to user security and corporate networks.
Researchers warn that this latest evolution of ClickFix-style manipulation demonstrates increasing sophistication in browser-based attack methods. The CrashFix Chrome extension highlights how easily familiar functionality, like ad blocking, can be repurposed for malicious ends.
Read the full report from The Hacker News for further technical details:
https://thehackernews.com/2026/01/crashfix-chrome-extension-delivers.html
