CrashFix is a ClickFix-style social-engineering campaign attributed by Huntress to the KongTuke threat actor. It uses malicious Chrome ad-blocking extensions, including extensions impersonating uBlock Origin Lite or presented as NexShield, which have been promoted through malicious advertisements and installed from the Chrome Web Store. The extensions retain apparent ad-blocking functionality but delay their malicious actions, then deliberately exhaust browser resources and crash Chrome. On restart, victims are shown a fraudulent security or recovery warning and instructed to paste and run a purported repair command through the Windows Run dialog or terminal. The extension covertly places a malicious PowerShell command on the clipboard, relying on victim-driven execution rather than exploitation.
The execution chain abuses the Windows Finger client and obfuscated PowerShell to retrieve additional stages. It performs anti-analysis and environment checks and selectively deploys more capable tooling to domain-joined enterprise systems. Observed payloads include a portable Python runtime and ModeloRAT, a Python-based remote-access trojan that communicates with attacker-controlled infrastructure, executes commands and additional payloads, and establishes Windows Registry Run-key persistence. Related activity has also used scheduled-task persistence. CrashFix primarily targets Windows systems and appears designed to prioritize higher-value corporate environments while using delayed execution, renamed legitimate utilities, scripting, and living-off-the-land techniques to reduce detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Huntress just published a report on a new ClickFix variant they’ve discovered, which they’ve dubbed CrashFix... using KongTuke’s malicious browser extension to display a fake security warning... prompting users to run a 'scan'... instructed to manually 'fix' the issue by opening the Windows Run dialog... The malicious extension silently copies a PowerShell command to the clipboard"
21 distinct techniques documented for this family, organized by ATT&CK tactic.
"...harnesses Windows tools and in-memory scripts to facilitate simultaneous delivery of various backdoors..." and "...launching the primary Python implant..."
"...silently copies a PowerShell command to the clipboard... From there, they execute the malicious command."
“obfuscated PowerShell using ROT cipher encoding… multiple layers of Base64 encoding and XOR… .NET payload adds two-layer encryption (AES-256 plus XOR)… string concatenation… junk code padding”
“copies finger.exe from System32 to the %temp% directory (renaming it to ct.exe to avoid detection)”
“downloads… saves… as script.ps1, executes it, and then deletes itself to remove evidence of the initial infection stage”
"abused a legitimate Windows binary – finger.exe – copied from System32, renamed, and executed... output... piped directly into cmd.exe... for an obfuscated PowerShell payload"
“Scans running processes for 50+ analysis tools… and VM indicators… If any are found, it exits immediately.” / “fingerprinting… distinguish a real victim from an analyst's sandbox.”
“Checks if the machine is domain-joined or standalone (WORKGROUP)… distinguish between corporate targets and home users.”
“Checks if the machine is domain-joined… Sends… installed antivirus products… runs… VM indicators… builds a unique numeric fingerprint… C2 server uses this value to determine whether… real hardware or… analysis environment”
“Checks if the machine is domain-joined or standalone (WORKGROUP)… Domain-joined gets the VIP Treatment”
“Scans running processes for 50+ analysis tools… and VM indicators… If any are found, it exits immediately.” / “fingerprinting… distinguish a real victim from an analyst's sandbox.”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A fake ad blocker that directs targets to the official Chrome Web Store and delays its first fraudulent alert for approximately an hour after installation, likely to obscure the causal link between installation and malicious behavior.
A ClickFix variant referenced as part of the broader trend toward Python-based RAT delivery; mentioned as related background rather than the focal malware in this incident.
A ClickFix variant referenced as background context for the broader shift toward Python-based remote-access trojans. It is not attributed to, or technically linked with, the IronPython-loader intrusion beyond this general delivery trend.
A ClickFix-style social-engineering variant that tricks users into copying and executing attacker-supplied commands, leading to staged payload delivery, persistence, and follow-on malware execution. In the Microsoft example, it led to obfuscated PowerShell, dropped scripts, a portable WinPython package, and execution of a Python RAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.