CrashFix attack hijacks browser failures to deliver ModelRAT malware via fake Chrome extension | CSO Online

The CrashFix attack uses a fake Chrome extension to intentionally crash browsers, then tricks users into running attacker-supplied commands to deploy the ModelRAT malware. This campaign, attributed to the KongTuke threat cluster, mimics ClickFix-style attacks by socially engineering victims into executing malicious code disguised as a system repair.

Edward Kiledjian @ekiledjian