HomeSecurityCrashFix: Fake notifications in users' browsers

CrashFix: Fake notifications in users' browsers

The threat, dubbed CrashFix, operates through a malicious Chrome extension that masquerades as the legitimate ad blocker NexShield.

See also: PLUGGYAPE malware targets Ukraine via Signal & WhatsApp

CrashFix
CrashFix: Fake notifications in users' browsers

Cybersecurity researchers have identified the sophisticated malware campaign, which uses an unusual but highly effective tactic: deliberately causing users' browsers to crash.

When users search for online privacy tools, malicious ads direct them to download a seemingly trustworthy extension from Chrome Web Store .

The fake extension launches a coordinated attack aimed at exhausting users’ patience and pushing them to execute dangerous commands. The campaign reveals a multi-layered infection method that targets both home and corporate networks. After installation, the extension remains inactive for the first hour before activating its destructive payload.

See also: Critical n8n vulnerability allows hackers full control

CrashFix: Fake notifications in users' browsers
CrashFix: Fake notifications in users' browsers

This time-delay strategy creates a gap between installation and the appearance of problems, making it harder for victims to link browser problems to recently installed software.

The operation demonstrates careful planning by the threat actors, who have a deep understanding of user behavior.

Huntress analysts pointed out that the campaign originates from the KongTuke threat group , which has been monitored and active since early 2025.

Researchers identified multiple sophisticated elements, such as the NexShield extension that mimics uBlock Origin Lite , the CrashFix attack mechanism , as well as a previously unknown Python-based remote access tool called ModeloRAT .

See also: Hackers exploit Google Cloud and steal Microsoft 365 login credentials

CrashFix: Fake notifications in users' browsers

Corporate targets appear to receive preferential treatment, as domain-joined systems receive more powerful malware compared to stand-alone systems, suggesting that attackers are prioritizing attacks against businesses.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS