Malware & RansomwareHIGH

CrashFix: Malicious Ad Blocker Crashes Browsers for Profit

Featured image for CrashFix: Malicious Ad Blocker Crashes Browsers for Profit
HNHuntress Blog
KongTukeCrashFixModeloRATmalicious extension
🎯

Basically, a fake ad blocker crashes your browser and tries to sell you a fix.

Quick Summary

KongTuke has launched a malicious ad blocker that crashes your browser. Users may unknowingly download it, risking their data and privacy. Experts are monitoring the situation and urging caution.

What Happened

Have you ever installed an ad blocker only to find your browser? acting strange? KongTuke, a known cybercriminal group?, has launched a new campaign called CrashFix that exploits this common scenario. The malicious extension? crashes users' browser?s and then offers a dubious 'fix' to regain control.

This campaign targets users by luring them into downloading a fake ad blocker. Once installed, the extension wreaks havoc on the browser?, causing it to crash repeatedly. After the chaos, the attackers present a solution — a malicious tool called ModeloRAT. This tool is designed for more sophisticated attacks, particularly against high-profile targets, turning a simple browser? issue into a gateway for serious cyber threats.

Why Should You Care

You might think, "This won’t happen to me," but it can. Imagine downloading a free app that promises to enhance your browsing experience, only to find it sabotaging your device instead. This is not just an inconvenience; it can expose your personal data and lead to larger security breaches.

Your online safety is at risk. If you fall for such scams, you could end up with malware that steals your information or even takes control of your device. It’s like inviting a stranger into your home under the guise of helping you fix a broken appliance, only to find they’ve stolen your valuables.

What's Being Done

Security experts are already tracking the CrashFix campaign. Browser? developers are working on patches and updates to prevent these malicious extension?s from being installed. Here’s what you can do right now:

  • Avoid downloading extensions from unverified sources.
  • Regularly update your browser to ensure you have the latest security features.
  • Use reputable antivirus software to detect and remove malware.

Experts are watching closely for how KongTuke evolves its tactics and whether other groups will adopt similar strategies. Stay vigilant and informed to protect yourself from these threats.

💡 Tap dotted terms for explanations

🔒 Pro insight: The CrashFix campaign exemplifies the shift towards browser-based attacks, leveraging user trust in extensions for exploitation.

Original article from

Huntress Blog

Read Full Article

Related Pings

HIGHMalware & Ransomware

Payload Ransomware - Breaches Royal Bahrain Hospital Data

Payload Ransomware claims to have breached Royal Bahrain Hospital, stealing 110 GB of sensitive data. Patients and the healthcare sector are at risk as the group threatens to leak this data if the ransom isn't paid. Urgent action is needed to protect sensitive information.

Security Affairs·
HIGHMalware & Ransomware

Malware - Latest Threats and Research Insights Explained

The latest malware newsletter reveals critical threats like BoryptGrab and A0Backdoor. These sophisticated attacks target users through deceptive methods, making awareness essential. Stay informed to protect your data and systems.

Security Affairs·
HIGHMalware & Ransomware

AppsFlyer SDK Hijacked to Deploy Crypto-Stealing Malware

What Happened This week, the AppsFlyer Web SDK was hijacked in a serious supply-chain attack. Malicious code was injected into the SDK, which is widely used for marketing analytics by over 15,000 businesses globally. The compromised code was designed to intercept cryptocurrency wallet addresses entered by users on various websites. Instead of sending funds to the intended wallet, the

BleepingComputer·
HIGHMalware & Ransomware

GlassWorm Campaign Exploits 72 Extensions to Target Developers

A new GlassWorm campaign exploits 72 malicious extensions targeting developers. This sophisticated attack uses seemingly harmless tools to deliver malware. Developers must stay vigilant to protect their systems from these threats.

The Hacker News·
HIGHMalware & Ransomware

Malicious npm Packages Steal Discord and Crypto Data

A sophisticated supply chain attack has emerged, targeting Discord and cryptocurrency wallets. Users of npm packages are at risk of having their sensitive data stolen. Immediate action is required to secure accounts and data.

Cyber Security News·
HIGHMalware & Ransomware

GlassWorm Malware Expands Reach with 72 Malicious Extensions

The GlassWorm malware campaign has escalated, infecting developer environments through 72 malicious Open VSX extensions. Developers using popular tools are at risk, as attackers employ clever tricks to bypass security measures. Immediate action is necessary to protect sensitive data and maintain secure coding practices.

Cyber Security News·