As cited
Copy frozen at (site build).
threat intel
Dissecting CrashFix: KongTuke's New Toy
KongTuke operates a deceptive campaign called CrashFix that delivers a fake ad blocker extension designed to deliberately crash user browsers, then prompts victims to install a fix that deploys ModeloRAT malware. The campaign appears to target higher-value victims for remote access and control.
Why it matters: Security teams and end users should watch for fake ad blocker installations and fraudulent browser repair tools, as this social engineering tactic chains commodity frustration with credential theft and malware deployment.
- Source published
- First seen by Cybersecurity Tracker