Automatically translated.View original post

Unmasking a new technique CrashFix found was used to fool the victim.

Unmasking a new technique CrashFix found was used to fool ModeloRAT malware installation victims.

ClickFix, or an unreal bug screen with instructions for the victim to do so to correct it, is actually a malware installation for the victim. It has been called a popular method over the past year. This method has developed so much that there are many sub-forms, such as in this news.

According to a report by the website, The Hacker News has mentioned the detection of a new type of ClickFix campaign that instead of fooling the website and causing the website to display a fake error message for the victim to follow the order. It is a trick for the victim to install an Extensions web browser, and then the extension will freeze the web browser (Crash) on purpose to trick the victim into following a command that will ultimately lead to a malware download. This method was named CrashFix by a research team from Huntress, a company of hackers experts who detected the gambit.

The research team has revealed that the system behind the CrashFix victim scam is the infrastructure of the Traffic or Traffic Distribution System (TDS) type that transforms the target of the victim's redirect website to a website where a payload of malware files is stored called KongTuke, known by many other names, 404 TDS, Chaya _ 002, LandUpdate808, and TAG-124. This system has been used by many hackers to spread a variety of malware, such as Rhysida Ransomware, Interlock. Ransomware, and TA866 (or Asylum Ambuscade), outside of the popularity of being used by different groups of hackers, are also reported to be involved in such famous malware as Socgholish and D3F@ck Loader.

In order to spread the fake add-on that is currently the case, hackers have created an ad blocker called "NexShield - Advanced Web Guardian," which boasts that it can block a lot of advertising. This add-on was once available for download via the official Google Chrome Web Store web browser add-on, which was downloaded by up to 5,000 victims before this fake add-on was deleted, which, according to the research team, is similar to the one. It complements a genuine Ad Blocker like uBlock Origin Lite version 2025.1116.1841, so much so that it is expected that the hackers behind it have made a copycat (Clone) to deceive the victim.

On the job side, after the victim installs the add-on, the add-on displays a Security Warning notification. The web browser is abnormally stopped, and the victim is instructed to scan for cyber threats that are detected by the Microsoft Edge web browser. If the victim scans, it will lead to another alert that will come with the command to activate Windows Run. Then paste the copy command on Run and press Enter (which is the same method as ClickFix). The web browser will also be put in a DoS (Denial-of-Service) extension until it ultimately freezes.

While the web browser is suspended, the input command leads to the download of the first PowerShell script from the control server (C2). After the first script is grounded, it leads to the download of the second PowerShell script. By malware or payload, the second will check for analysis tools and more than 50 Virtual Machines. If the payload is detected, it will stop immediately. In addition to that, it will be checked that the unit is active. Use Domain-Joined or Standalone. After the verification is complete, the payload sends two data back to the C2 server.

A list of all anti-virus software installed on the machine.

Two machine type indications

"ABCD111" for singular machines

"WORKGROUP" or "BCDA222" for domain-sharing machines

If the machine is detected as a co-domain machine, the TDS system will work to release a payload of ModeloRAT malware, a malware type that controls the victim's machine, or a RAT (Remote Access Trojan) that focuses on attacks on the Windows operating system, and an RC4 encryption system is used to communicate with the C2 server located on the IP Address number "170.168.103 [.] 208" or "158.247.252. [.] 178 "comes down on the machine and creates Persitence through the Registry modification and manipulates the use of the corresponding inaries, DLLs, Python scripts, and PowerShell commands.

The ModeloRAT malware, although its capabilities are not mentioned by the source, mentions some of its functionality. The malware has the ability to update itself through the "VERSION _ UPDATE" command or delete itself with the "TERMINATION _ SIGNAL" command received from the C2 server.

# hacking # Trending # lemon 8 diary # Lemon 8 Howtoo # freedomhack

2/9 Edited to

... Read moreจากประสบการณ์ส่วนตัวของผมที่ทำงานด้านไอทีและความปลอดภัยไซเบอร์ ผมเห็นได้ว่าเทคนิคหลอกลวงผ่านส่วนเสริมเบราว์เซอร์กำลังกลายเป็นภัยที่ร้ายแรงขึ้นเรื่อยๆ ซึ่งผู้ใช้ทั่วไปมักไม่ทันระวังเพราะส่วนเสริมเหล่านี้มักถูกนำเสนอในลักษณะเหมือนกับแอปหรือฟีเจอร์ที่เป็นประโยชน์ เช่น บล็อกโฆษณา จึงทำให้ผู้ใช้หลงเชื่อและติดตั้งโดยไม่รู้ตัว ในกรณีของ CrashFix และมัลแวร์ ModeloRAT นั้น สิ่งที่น่ากลัวคือขั้นตอนการแพร่กระจายที่ใช้กลไกขั้นสูง เช่น การจำลองข้อความแจ้งเตือนความปลอดภัยเทียม และการสั่งให้ผู้ใช้ใช้คำสั่งจากตัวส่วนเสริมโดยตรงเพื่อดาวน์โหลดสคริปต์อันตราย โดยที่เหยื่อคิดว่ากำลังแก้ไขปัญหาเว็บเบราว์เซอร์เพียงอย่างเดียวเท่านั้น ผมเคยรับมือกับเหยื่อที่ติดมัลแวร์ประเภท RAT ที่ทำให้แฮกเกอร์สามารถเข้าควบคุมเครื่องได้ทั้งหมด เรียกได้ว่าเหมือนเปิดประตูหลังเครื่องคอมพิวเตอร์ให้กับผู้ไม่หวังดีอย่างเต็มใจโดยไม่รู้ตัว การถูกมัลแวร์แบบนี้โจมตีไม่เพียงแต่เสี่ยงข้อมูลส่วนตัวและงานสำคัญสูญหาย แต่ยังเป็นจุดเริ่มต้นของการวิ่งเข้าหาช่องโหว่ต่างๆ ในระบบเครือข่ายขององค์กรด้วย คำแนะนำที่ผมมักย้ำเสมอคือ ควรติดตั้งส่วนเสริมเฉพาะจากแหล่งที่น่าเชื่อถือและตรวจสอบรีวิวให้ละเอียด รวมถึงควรใช้โซลูชันแอนตี้มัลแวร์ที่อัปเดตใหม่อยู่เสมอ เพื่อป้องกันไม่ให้ส่วนเสริมปลอมซ่อนตัวเข้ามาได้ รวมทั้งหากพบข้อความแจ้งเตือนผิดปกติจากส่วนเสริมที่เพิ่งติดตั้ง ควรงดทำตามคำแนะนำทันทีและตรวจสอบอย่างละเอียดก่อน ในเชิงเทคนิค เทคนิคการยิง DoS ใส่เว็บเบราว์เซอร์เพื่อหลอกให้ค้าง รวมถึงการใช้ PowerShell สคริปต์หลายขั้นตอนเพื่อตรวจสอบสภาพแวดล้อมและดักจับในระบบจำลอง นับว่าเป็นการปรับปรุงขั้นสูงของกลุ่มแฮกเกอร์ในยุคนี้ ซึ่งผู้ใช้งานธรรมดาที่ไม่รู้จักเรื่องเหล่านี้ยากที่จะป้องกันได้หากไม่มีความรู้และเครื่องมือที่เหมาะสม สุดท้าย การเข้าใจและตื่นตัวเกี่ยวกับกลเม็ดใหม่ ๆ ของมัลแวร์เช่น CrashFix และ ModeloRAT จะช่วยลดความเสี่ยงที่จะตกเป็นเหยื่อได้มากขึ้น ขอแนะนำให้ทุกคนแชร์ข้อมูลเกี่ยวกับภัยเหล่านี้และอัปเดตความรู้กับทีมไอทีหรือผู้เชี่ยวชาญอย่างสม่ำเสมอ เพื่อให้สามารถรับมือได้ทันกับเทคนิคใหม่ๆ ที่เกิดขึ้นอย่างต่อเนื่อง

Related posts

DARK PSYCHOLOGY 101 👁️‍🗨️🔮
#books you may want to add to your #library 🙏🏾🙏🏾🙏🏾
Alchemist Godbody

Alchemist Godbody

578 likes

Police Save Little Girl After Terrifying Escape From Dangerous Mother #cops #bodycam
Jaynelle

Jaynelle

207 likes

Unmasking ADHD in Women and Young Girls
After living undiagnosed with ADHD for 39yrs, Martha explores the reasons girls and women are underdiagnosed and her lived experiences before and after her 2021 diagnosis. Martha Barnard-Rae writes clear, convincing words for exacting humans. As a copywriter and owner of Word Candy, she specia
EasyToDo

EasyToDo

23 likes

Simple Ways to End Anxiety and Panic Attacks ♥️♥️♥️
#growthjourney #growthmindset #growth #posh #anxious
POSH🌸

POSH🌸

5 likes

Let me reintroduce myself....
LetsGlowKimber

LetsGlowKimber

2 likes

your mind is preventing you from getting what
#CapCut #mindsetinmotion #minds #mindsetpower #subconsciousmind
arnoldaustin231

arnoldaustin231

1 like

Unmasking the Lies, Embracing the Truth
🌹 Read this if you’ve ever felt like you were “too much. For years, many of us were told to shrink, silence our voices, and sacrifice our joy just to be “chosen.” But the truth is—real love doesn’t demand your brokenness, it embraces your wholeness. 💎 Sis, you are not too much. You are enoug
Coach Jen

Coach Jen

19 likes

End the Cycle of Overthinking & Live in the Moment
I know you’ve been there. You finish a conversation, maybe it’s with a friend, a coworker, or even someone you’re talking to for the first time, and then... boom. You’re stuck in your head replaying every word, every expression, every little thing you said and did. It’s like a broken record, and I’
Chalie_Baker

Chalie_Baker

77 likes

SATURDAY | 2 MAY 2026 | The A.I. Sector
The line between man and machine? It just blurred. 🧬💻 Host Arias Thomas** breaks down the biggest shifts in the digital sprawl for May 2nd, 2026. From GPT-7 modules talking to human cells to the SEC finally unmasking the "Black Box" of Wall Street, the frontier is moving faster than
Cyber F.M.

Cyber F.M.

0 likes

Unmasking troubles 🤣
Hahahahahahahaha....ahhhhhh 🫠 . . . . #unmaskedautistic #unmasking #healing #trauma #neurodivergent #relatable #relate #skit #audhd #autism #adhd #tempyvixen
TempyVixen

TempyVixen

4 likes

Unmasking Autism = Healing ❤️‍🩹
#autism #nostalgia #autisticgirl #stimming #neurodivergent
Rachel 🌈♾️

Rachel 🌈♾️

5 likes

Let’s Heal…
#healingthemagic #healingvibrations #healingqueen #letschat #lemon8 #lemon8diary #lemon8diarychallenge #gamergirl
Novelist Davis

Novelist Davis

5 likes

#transtruth #viral #fyp #ct #transpective
Rawr xD Yuna🌙The.Terror.

Rawr xD Yuna🌙The.Terror.

0 likes

TC

TC

1 like

#creatorsearchinsights Police Save Little Girl After Terrifying Escape From Dangerous Mother #cops #karma
1875.copsusa

1875.copsusa

6 likes

#unmasking #paintingreveal #art #CapCut
Sol Summers

Sol Summers

1 like

🧿🪬OkieBerry🪬 🧿

🧿🪬OkieBerry🪬 🧿

1 like

@minji Listen here: https://podcasts.apple.com/us/podcast/201-taking-back-the-narrative-unmasking-the-fetish/id1260925014?i=1000722130983 #asianamerican
Kaila Yu

Kaila Yu

0 likes

Unmasking as a Neurodivergent
Unmasking makes your life feel like it’s falling apart, but it’s actually consciously coming together for the first time, brick by brick. This is why I’ve created the fitness community for neurodivergents with longevity fitness goals. The community is called Moving Unmasked, because I want to
Emily | Women’s Fitness

Emily | Women’s Fitness

1 like

Neurodivergent Comfort Over EVERYTHING PART1
What do you do when your neurodivergent loved one is behaving in a way that makes other people uncomfortable? The most important thing you can do is reframe your perception of what is happening. Because a lot of people will see the behavior as undesirable and punish , when the reality is, this p
SupportTheSpectrum

SupportTheSpectrum

4 likes

I met them all (Belle Cosplay)
Belle Cosplay! #katiew1011 #beautyandthebeast #belle #bellecosplay #cosplay
Katie W🥀🎭🎬

Katie W🥀🎭🎬

39 likes

Paige Gilson

Paige Gilson

0 likes

Signs She’s Fake Interested
Unmasking the signs of fake interest in dating! 💔✨ If you want to know whether she’s genuinely into you or just playing games, check out my latest video on YouTube at DreamCarQueen. Your heart deserves the truth! #lovegames #singlelife #formen #datingstruggles
dreamcarqueen

dreamcarqueen

2 likes

recording these videos in one take is forcing me to have more self trust in what needs to be said. But also in knowing that the words that come to mind are exactly what I am supposed to say in the moment ✨ I hope you enjoy this stream of consciousness as much as I enjoyed sharing. And for me
Lindsey

Lindsey

1 like

narc facts
#narccist #narctok #narcknowledge #narcmagnet #narc
andrea35reiss

andrea35reiss

2 likes

Unmasking my ADHD
I started masking My ADHD when I entered elementary school. When I was younger in pre-k and kindergarten I was able to be myself without much repercussions. Once I started hitting the years where academics was the focus, I was always in trouble for being “too loud” or “too chatty” or not organized
Danielle

Danielle

30 likes

Ella

Ella

1 like

Day 3 Unmasking as a Neurodivergent with CPTSD
#UnmaskingChallenge #InnerChildHealing #NeurodivergentVoices #CPTSDRecovery #HealingJourney #BreakingCycles #TraumaRecovery #ResilientSoul #YouAreMoreThanEnough
YAMTE Always

YAMTE Always

1 like

A woman in a white tank top and blue cap poses on a mountain trail, with text overlay "Supplements For The ADHD" and stars. Mountains and trees are in the background.
Beyond Meds: Unmasking Supplements for ADHD WINS
Hey ADHD Babes, Let’s talk real for a second – managing ADHD can be a not so fun rollercoaster. Here are three supplements that might just add a little extra oomph to your toolkit. 📌 I’ll go into depth and deeper research in the next few posts about these supplements! 1. Omega-3 Fatty Aci
Alena Artemenko

Alena Artemenko

103 likes

The Belief Code is an energy healing technique that removes belief systems contributing to physical, emotional, and mental symptoms. This helps remove beliefs you have about yourself, other people, and the world around you which is holding you back. For more information and private sessions check o
Samantha 🧲 Energy Healing

Samantha 🧲 Energy Healing

0 likes

Mini Book Haul- Allie Cole Book one- Daughter of Darkness Wielder of Shadows Book two- Daughter of Darkness Prince of Bloodshed #enemiestolovers #bookhaul #books #romantasy #slowburn
📚DistortedBlissReads📚

📚DistortedBlissReads📚

4 likes

Autism
#autism #read #book #learn
Daily Dose of Inspo

Daily Dose of Inspo

44 likes

Neurodivergent Comfort Over EVERYTHING part 3
What do you do when your neurodivergent loved one is behaving in a way that makes other people uncomfortable? The most important thing you can do is reframe your perception of what is happening. Because a lot of people will see the behavior as undesirable and punish , when the reality is, this p
SupportTheSpectrum

SupportTheSpectrum

2 likes

#lemon8diarychallenge
Londyn

Londyn

1 like

Tea4Me

Tea4Me

1 like

See more