CrashFix is a ClickFix-style social-engineering malware delivery cluster that deliberately crashes a victim’s browser and then coerces the user into executing attacker-supplied commands on Windows. It has been observed delivered through malicious browser extensions masquerading as legitimate ad blockers, including extensions impersonating uBlock Origin Lite and a malicious extension known as NexShield, often promoted through malicious advertising and installed from the Chrome Web Store to create a false sense of legitimacy. After a delay intended to reduce suspicion, the extension forces a browser denial-of-service and displays a fake recovery or security warning instructing the victim to open the Windows Run dialog or terminal and paste a command that the extension has already copied to the clipboard.
The executed command chain abuses native Windows utilities, especially finger.exe, sometimes copied and renamed to hinder detection, to retrieve and run additional obfuscated scripts. Observed follow-on stages include PowerShell downloaders, anti-analysis and virtual-machine checks, domain-join awareness, deployment of portable Python runtimes such as WinPython or IronPython, and execution of Python-based payloads entirely or largely in memory. On higher-value or domain-joined systems, CrashFix has been associated with delivery of Python remote-access tooling including ModeloRAT, while other observed chains culminated in in-memory code execution, process injection into explorer.exe, and keylogging. Persistence has been established through Run-key entries and scheduled tasks.
CrashFix is notable for combining user-driven execution, living-off-the-land binaries, staged Python payloads, and selective targeting logic. Reported capabilities include command execution, reconnaissance, anti-analysis checks, payload retrieval, persistence, process injection, and credential or session theft-related behaviors such as keylogging. Reporting has linked some CrashFix activity to the KongTuke threat actor, while other observed CrashFix/ClickFix intrusion chains have not been publicly attributed. The activity appears oriented toward enterprise and other high-value Windows environments, with domain-joined hosts receiving more capable follow-on malware than standalone systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Huntress just published a report on a new ClickFix variant they’ve discovered, which they’ve dubbed CrashFix... using KongTuke’s malicious browser extension to display a fake security warning... prompting users to run a 'scan'... instructed to manually 'fix' the issue by opening the Windows Run dialog... The malicious extension silently copies a PowerShell command to the clipboard"
21 distinct techniques documented for this family, organized by ATT&CK tactic.
"...harnesses Windows tools and in-memory scripts to facilitate simultaneous delivery of various backdoors..." and "...launching the primary Python implant..."
"...silently copies a PowerShell command to the clipboard... From there, they execute the malicious command."
“obfuscated PowerShell using ROT cipher encoding… multiple layers of Base64 encoding and XOR… .NET payload adds two-layer encryption (AES-256 plus XOR)… string concatenation… junk code padding”
“copies finger.exe from System32 to the %temp% directory (renaming it to ct.exe to avoid detection)”
“downloads… saves… as script.ps1, executes it, and then deletes itself to remove evidence of the initial infection stage”
"abused a legitimate Windows binary – finger.exe – copied from System32, renamed, and executed... output... piped directly into cmd.exe... for an obfuscated PowerShell payload"
“Scans running processes for 50+ analysis tools… and VM indicators… If any are found, it exits immediately.” / “fingerprinting… distinguish a real victim from an analyst's sandbox.”
“Checks if the machine is domain-joined or standalone (WORKGROUP)… distinguish between corporate targets and home users.”
“Checks if the machine is domain-joined… Sends… installed antivirus products… runs… VM indicators… builds a unique numeric fingerprint… C2 server uses this value to determine whether… real hardware or… analysis environment”
“Checks if the machine is domain-joined or standalone (WORKGROUP)… Domain-joined gets the VIP Treatment”
“Scans running processes for 50+ analysis tools… and VM indicators… If any are found, it exits immediately.” / “fingerprinting… distinguish a real victim from an analyst's sandbox.”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ClickFix variant referenced as part of the broader trend toward Python-based RAT delivery; mentioned as related background rather than the focal malware in this incident.
A ClickFix-style social-engineering variant that tricks users into copying and executing attacker-supplied commands, leading to staged payload delivery, persistence, and follow-on malware execution. In the Microsoft example, it led to obfuscated PowerShell, dropped scripts, a portable WinPython package, and execution of a Python RAT.
A ClickFix-style endpoint compromise technique delivered via a malicious browser extension that presents fake security warnings and coerces the user into executing a clipboard-copied PowerShell command through the Windows Run dialog, resulting in execution of attacker-controlled code.
Chrome-extension-based technique that intentionally crashes the browser (DoS) and socially engineers the user into executing attacker-provided commands; newer variants use push-notification-based C2 to selectively trigger crashes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.