Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How to watch Paradise season 2 online from anywhere

    What’s The Difference Between A Biker, A Rider, & A Motorcyclist? It’s Complicated

    A Knight of the Seven Kingdoms season 1 ending explained: what happens to Dunk and Egg, will there be a season 2, and more

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026
    • Business

      Gartner: Why neoclouds are the future of GPU-as-a-Service

      February 21, 2026

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026
    • Crypto

      3 Altcoins Crypto Whales are Buying After Supreme Court’s Trump Tariff Ban

      February 22, 2026

      SBI Deepens XRP Bet With Bond Incentives and Venture Studio Plan

      February 22, 2026

      IoTeX Hit by Private Key Exploit, Attacker Drains Over $2 Million

      February 22, 2026

      Solana Price Faces a Bull Trap as 50% Holders Exit

      February 22, 2026

      XRP Flaunts a 3-Week ETF Inflow Streak, So Why is Price Still Stuck Below $1.50?

      February 22, 2026
    • Technology

      How to watch Paradise season 2 online from anywhere

      February 23, 2026

      What’s The Difference Between A Biker, A Rider, & A Motorcyclist? It’s Complicated

      February 23, 2026

      A Knight of the Seven Kingdoms season 1 ending explained: what happens to Dunk and Egg, will there be a season 2, and more

      February 23, 2026

      4 Things You Didn’t Know HDMI Ports Can Do

      February 23, 2026

      The FBI Says These Wi-Fi Routers Are Unsafe, And Here’s Why

      February 23, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Fake ad blocker extension crashes the browser for ClickFix attacks
    Technology

    Fake ad blocker extension crashes the browser for ClickFix attacks

    TechAiVerseBy TechAiVerseJanuary 20, 2026No Comments4 Mins Read1 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Fake ad blocker extension crashes the browser for ClickFix attacks
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Fake ad blocker extension crashes the browser for ClickFix attacks

    A malvertising campaign is using a fake ad-blocking Chrome and Edge extension named NexShield that intentionally crashes the browser in preparation for ClickFix attacks.

    The attacks were spotted earlier this month and delivered a new Python-based remote access tool called ModeloRAT that is deployed in corporate environments.

    The NexShield extension, which has been removed from the Chrome Web Store, was promoted as a privacy-first, high-performance, lightweight ad blocker created by Raymond Hill, the original developer of the legitimate uBlock Origin ad blocker with more than 14 million users.

    The NexShield website
    Source: Huntress

    Researchers at managed security company Huntress say that NexShield creates a denial-of-service (DoS) condition in the browser by creating ‘chrome.runtime’ port connections in an infinite loop and exhausting its memory resources.

    This results in frozen tabs, elevated CPU usage in the Chrome process, increased RAM usage, and general browser unresponsiveness. Eventually, Chrome/Edge hangs or crashes, forcing a kill via the Windows Task Manager.

    Because of this, Huntress refers to these attacks as a variant of ClickFix that they named ‘CrashFix’.

    When the browser is restarted, the extension displays a deceptive pop-up that shows a fake warning and suggests scanning the system locate the problem.

    The deceptive pop-up served on browser restart
    Source: Huntress

    Doing so opens a new window with a fake warning about security issues detected that threaten the user’s data, with instructions on how to fix the problem, which involve executing malicious commands in the Windows command prompt.

    In typical ClickFix fashion, the malicious extension copies a command to the clipboard and instructs the user to just hit ‘Ctrl+V’ and then run it in Command Prompt.

    The ‘fixing’ command is a chain that triggers an obfuscated PowerShell script via a remote connection, which downloads and executes a malicious script.

    The ClickFix stage of the attack
    Source: Huntress

    In an attempt to dissociate the extension from the malicious activity and evade detection, the payload has a 60-minute execution delay after installing NexShield.

    For domain-joined hosts specific to corporate environments, the threat actor delivers ModeloRAT, which can perform system reconnaissance, execute PowerShell commands, modify the Registry, introduce additional payloads, and update itself.

    Commands supported by ModeloRAT
    Source: Huntress

    For non-domain hosts, which are normally home users, the command and control server returned a “TEST PAYLOAD!!!!” message, indicating either low priority or work in progress, Huntress researchers say.

    Earlier this month, cybersecurity company Securonix spotted another ClickFix attack that simulated a Windows BSOD screen in the target browser by abusing the full-screen mode; however, in the case of CrashFix, the browser crash is real, making it more convincing.

    The researchers provide a proper technical report on the entire CrashFix attack and the payloads delivered this way. They detail the multiple stages of the infection chain and ModeloRAT’s capabilities, from establishing persistence and collecting reconnaissance info to executing commands, fingerprinting systems, and determining its privileges on the compromised system.

    Huntress attributes the analyzed CrashFix attack to a threat actor named ‘KongTuke’, whose operations have been on the company’s radar since early 2025.

    Based on the recent discovery, the researchers believe that KongTuke is evolving and becoming more interested in enterprise networks, which are more lucrative for cybercriminals.

    Falling for ClickFix attacks can be prevented by making sure that the effect of any external command executed on the system is well understood. Furthermore, installing browser extensions from trusted publishers or sources should keep you safe from CrashFix attacks or other threats.

    Users who installed NexShield should perform a full system cleanup, as uninstalling the extension does not remove all payloads, such as ModeloRAT or other malicious scripts.


    The 2026 CISO Budget Benchmark

    It’s budget season! Over 300 CISOs and security leaders have shared how they’re planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

    Learn how top leaders are turning investment into measurable impact.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleNew PDFSider Windows malware deployed on Fortune 100 firm’s network
    Next Article You can get ChatGPT’s $20 Plus subscription for free for a limited time
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    How to watch Paradise season 2 online from anywhere

    February 23, 2026

    What’s The Difference Between A Biker, A Rider, & A Motorcyclist? It’s Complicated

    February 23, 2026

    A Knight of the Seven Kingdoms season 1 ending explained: what happens to Dunk and Egg, will there be a season 2, and more

    February 23, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025689 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025277 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025159 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025120 Views
    Don't Miss
    Technology February 23, 2026

    How to watch Paradise season 2 online from anywhere

    How to watch Paradise season 2 online from anywhere (Image credit: Anne Marie Fox/Disney) Xavier…

    What’s The Difference Between A Biker, A Rider, & A Motorcyclist? It’s Complicated

    A Knight of the Seven Kingdoms season 1 ending explained: what happens to Dunk and Egg, will there be a season 2, and more

    4 Things You Didn’t Know HDMI Ports Can Do

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    How to watch Paradise season 2 online from anywhere

    February 23, 20262 Views

    What’s The Difference Between A Biker, A Rider, & A Motorcyclist? It’s Complicated

    February 23, 20262 Views

    A Knight of the Seven Kingdoms season 1 ending explained: what happens to Dunk and Egg, will there be a season 2, and more

    February 23, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.