Malware & RansomwareHIGH

CrashFix: Malicious Ad Blocker Crashes Browsers for Profit

HNHuntress BlogJan 16, 2026
KongTukeCrashFixModeloRATmalicious extension
🎯

Basically, a fake ad blocker crashes your browser and tries to sell you a fix.

Quick Summary

KongTuke has launched a malicious ad blocker that crashes your browser. Users may unknowingly download it, risking their data and privacy. Experts are monitoring the situation and urging caution.

What Happened

Have you ever installed an ad blocker only to find your browser? acting strange? KongTuke, a known cybercriminal group?, has launched a new campaign called CrashFix that exploits this common scenario. The malicious extension? crashes users' browser?s and then offers a dubious 'fix' to regain control.

This campaign targets users by luring them into downloading a fake ad blocker. Once installed, the extension wreaks havoc on the browser?, causing it to crash repeatedly. After the chaos, the attackers present a solution — a malicious tool called ModeloRAT. This tool is designed for more sophisticated attacks, particularly against high-profile targets, turning a simple browser? issue into a gateway for serious cyber threats.

Why Should You Care

You might think, "This won’t happen to me," but it can. Imagine downloading a free app that promises to enhance your browsing experience, only to find it sabotaging your device instead. This is not just an inconvenience; it can expose your personal data and lead to larger security breaches.

Your online safety is at risk. If you fall for such scams, you could end up with malware that steals your information or even takes control of your device. It’s like inviting a stranger into your home under the guise of helping you fix a broken appliance, only to find they’ve stolen your valuables.

What's Being Done

Security experts are already tracking the CrashFix campaign. Browser? developers are working on patches and updates to prevent these malicious extension?s from being installed. Here’s what you can do right now:

  • Avoid downloading extensions from unverified sources.
  • Regularly update your browser to ensure you have the latest security features.
  • Use reputable antivirus software to detect and remove malware.

Experts are watching closely for how KongTuke evolves its tactics and whether other groups will adopt similar strategies. Stay vigilant and informed to protect yourself from these threats.

💡 Tap dotted terms for explanations

🔒 Pro insight: The CrashFix campaign exemplifies the shift towards browser-based attacks, leveraging user trust in extensions for exploitation.

Original article from

Huntress Blog

Read Full Article

Related Pings

HIGHMalware & Ransomware

ClickFix Attackers Evolve Tactics to Bypass Security Measures

Microsoft warns about a new ClickFix phishing tactic. Attackers are tricking users into executing harmful commands via Windows Terminal. This method can compromise your data and security. Stay alert and educate yourself on these evolving threats!

CSO Online·Yesterday, 9:15 PM
HIGHMalware & Ransomware

Fake Google Meet Update Gives Attackers Control of Your PC

A fake Google Meet update is tricking users into giving hackers control of their PCs. This poses a serious risk to personal and sensitive data. Stay vigilant and avoid suspicious update prompts to protect yourself.

Malwarebytes Labs·Yesterday, 7:35 PM
HIGHMalware & Ransomware

Spyware Masquerades as Emergency App Targeting Israeli Smartphones

Israeli smartphones were targeted by spyware disguised as an emergency app. This deceptive tactic puts personal data at risk. Stay vigilant and verify app legitimacy to protect your privacy.

The Register Security·Yesterday, 6:56 PM
HIGHMalware & Ransomware

Metasploit Update: New Exploits and Enhanced Control Features

Metasploit has launched a new update with powerful exploits and features. Users of Tactical RMM and MajorDoMo are particularly at risk. Stay ahead of potential attacks by updating your systems and reviewing security measures.

Rapid7 Blog·Yesterday, 6:28 PM
HIGHMalware & Ransomware

New ClickFix Attack Uses Windows Terminal for Malicious Payloads

A new wave of ClickFix attacks targets Windows Terminal to deliver malicious payloads. Users are at risk of unauthorized access and data theft. Stay cautious and keep your software updated to protect yourself.

Cyber Security News·Yesterday, 6:05 PM
HIGHMalware & Ransomware

AI-Powered Malware: Transparent Tribe Targets India

A hacking group is using AI to create malware targeting India. This mass production of implants could compromise personal data and financial security. Experts recommend updating software and using strong passwords to protect against these threats.

The Hacker News·Yesterday, 3:11 PM