The threat, dubbed CrashFix, operates through a malicious Chrome extension that masquerades as the legitimate ad blocker NexShield.
See also: PLUGGYAPE malware targets Ukraine via Signal & WhatsApp

Cybersecurity researchers have identified the sophisticated malware campaign, which uses an unusual but highly effective tactic: deliberately causing users' browsers to crash.
When users search for online privacy tools, malicious ads direct them to download a seemingly trustworthy extension from Chrome Web Store .
The fake extension launches a coordinated attack aimed at exhausting users’ patience and pushing them to execute dangerous commands. The campaign reveals a multi-layered infection method that targets both home and corporate networks. After installation, the extension remains inactive for the first hour before activating its destructive payload.
See also: Critical n8n vulnerability allows hackers full control

This time-delay strategy creates a gap between installation and the appearance of problems, making it harder for victims to link browser problems to recently installed software.
The operation demonstrates careful planning by the threat actors, who have a deep understanding of user behavior.
Huntress analysts pointed out that the campaign originates from the KongTuke threat group , which has been monitored and active since early 2025.
Researchers identified multiple sophisticated elements, such as the NexShield extension that mimics uBlock Origin Lite , the CrashFix attack mechanism , as well as a previously unknown Python-based remote access tool called ModeloRAT .
See also: Hackers exploit Google Cloud and steal Microsoft 365 login credentials

Corporate targets appear to receive preferential treatment, as domain-joined systems receive more powerful malware compared to stand-alone systems, suggesting that attackers are prioritizing attacks against businesses.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
