Automatically translated.View original post

Unmasking a new technique CrashFix found was used to fool the victim.

Unmasking a new technique CrashFix found was used to fool ModeloRAT malware installation victims.

ClickFix, or an unreal bug screen with instructions for the victim to do so to correct it, is actually a malware installation for the victim. It has been called a popular method over the past year. This method has developed so much that there are many sub-forms, such as in this news.

According to a report by the website, The Hacker News has mentioned the detection of a new type of ClickFix campaign that instead of fooling the website and causing the website to display a fake error message for the victim to follow the order. It is a trick for the victim to install an Extensions web browser, and then the extension will freeze the web browser (Crash) on purpose to trick the victim into following a command that will ultimately lead to a malware download. This method was named CrashFix by a research team from Huntress, a company of hackers experts who detected the gambit.

The research team has revealed that the system behind the CrashFix victim scam is the infrastructure of the Traffic or Traffic Distribution System (TDS) type that transforms the target of the victim's redirect website to a website where a payload of malware files is stored called KongTuke, known by many other names, 404 TDS, Chaya _ 002, LandUpdate808, and TAG-124. This system has been used by many hackers to spread a variety of malware, such as Rhysida Ransomware, Interlock. Ransomware, and TA866 (or Asylum Ambuscade), outside of the popularity of being used by different groups of hackers, are also reported to be involved in such famous malware as Socgholish and D3F@ck Loader.

In order to spread the fake add-on that is currently the case, hackers have created an ad blocker called "NexShield - Advanced Web Guardian," which boasts that it can block a lot of advertising. This add-on was once available for download via the official Google Chrome Web Store web browser add-on, which was downloaded by up to 5,000 victims before this fake add-on was deleted, which, according to the research team, is similar to the one. It complements a genuine Ad Blocker like uBlock Origin Lite version 2025.1116.1841, so much so that it is expected that the hackers behind it have made a copycat (Clone) to deceive the victim.

On the job side, after the victim installs the add-on, the add-on displays a Security Warning notification. The web browser is abnormally stopped, and the victim is instructed to scan for cyber threats that are detected by the Microsoft Edge web browser. If the victim scans, it will lead to another alert that will come with the command to activate Windows Run. Then paste the copy command on Run and press Enter (which is the same method as ClickFix). The web browser will also be put in a DoS (Denial-of-Service) extension until it ultimately freezes.

While the web browser is suspended, the input command leads to the download of the first PowerShell script from the control server (C2). After the first script is grounded, it leads to the download of the second PowerShell script. By malware or payload, the second will check for analysis tools and more than 50 Virtual Machines. If the payload is detected, it will stop immediately. In addition to that, it will be checked that the unit is active. Use Domain-Joined or Standalone. After the verification is complete, the payload sends two data back to the C2 server.

A list of all anti-virus software installed on the machine.

Two machine type indications

"ABCD111" for singular machines

"WORKGROUP" or "BCDA222" for domain-sharing machines

If the machine is detected as a co-domain machine, the TDS system will work to release a payload of ModeloRAT malware, a malware type that controls the victim's machine, or a RAT (Remote Access Trojan) that focuses on attacks on the Windows operating system, and an RC4 encryption system is used to communicate with the C2 server located on the IP Address number "170.168.103 [.] 208" or "158.247.252. [.] 178 "comes down on the machine and creates Persitence through the Registry modification and manipulates the use of the corresponding inaries, DLLs, Python scripts, and PowerShell commands.

The ModeloRAT malware, although its capabilities are not mentioned by the source, mentions some of its functionality. The malware has the ability to update itself through the "VERSION _ UPDATE" command or delete itself with the "TERMINATION _ SIGNAL" command received from the C2 server.

# hacking # Trending # lemon 8 diary # Lemon 8 Howtoo # freedomhack

2/9 Edited to

... Read moreจากประสบการณ์ส่วนตัวของผมที่ทำงานด้านไอทีและความปลอดภัยไซเบอร์ ผมเห็นได้ว่าเทคนิคหลอกลวงผ่านส่วนเสริมเบราว์เซอร์กำลังกลายเป็นภัยที่ร้ายแรงขึ้นเรื่อยๆ ซึ่งผู้ใช้ทั่วไปมักไม่ทันระวังเพราะส่วนเสริมเหล่านี้มักถูกนำเสนอในลักษณะเหมือนกับแอปหรือฟีเจอร์ที่เป็นประโยชน์ เช่น บล็อกโฆษณา จึงทำให้ผู้ใช้หลงเชื่อและติดตั้งโดยไม่รู้ตัว ในกรณีของ CrashFix และมัลแวร์ ModeloRAT นั้น สิ่งที่น่ากลัวคือขั้นตอนการแพร่กระจายที่ใช้กลไกขั้นสูง เช่น การจำลองข้อความแจ้งเตือนความปลอดภัยเทียม และการสั่งให้ผู้ใช้ใช้คำสั่งจากตัวส่วนเสริมโดยตรงเพื่อดาวน์โหลดสคริปต์อันตราย โดยที่เหยื่อคิดว่ากำลังแก้ไขปัญหาเว็บเบราว์เซอร์เพียงอย่างเดียวเท่านั้น ผมเคยรับมือกับเหยื่อที่ติดมัลแวร์ประเภท RAT ที่ทำให้แฮกเกอร์สามารถเข้าควบคุมเครื่องได้ทั้งหมด เรียกได้ว่าเหมือนเปิดประตูหลังเครื่องคอมพิวเตอร์ให้กับผู้ไม่หวังดีอย่างเต็มใจโดยไม่รู้ตัว การถูกมัลแวร์แบบนี้โจมตีไม่เพียงแต่เสี่ยงข้อมูลส่วนตัวและงานสำคัญสูญหาย แต่ยังเป็นจุดเริ่มต้นของการวิ่งเข้าหาช่องโหว่ต่างๆ ในระบบเครือข่ายขององค์กรด้วย คำแนะนำที่ผมมักย้ำเสมอคือ ควรติดตั้งส่วนเสริมเฉพาะจากแหล่งที่น่าเชื่อถือและตรวจสอบรีวิวให้ละเอียด รวมถึงควรใช้โซลูชันแอนตี้มัลแวร์ที่อัปเดตใหม่อยู่เสมอ เพื่อป้องกันไม่ให้ส่วนเสริมปลอมซ่อนตัวเข้ามาได้ รวมทั้งหากพบข้อความแจ้งเตือนผิดปกติจากส่วนเสริมที่เพิ่งติดตั้ง ควรงดทำตามคำแนะนำทันทีและตรวจสอบอย่างละเอียดก่อน ในเชิงเทคนิค เทคนิคการยิง DoS ใส่เว็บเบราว์เซอร์เพื่อหลอกให้ค้าง รวมถึงการใช้ PowerShell สคริปต์หลายขั้นตอนเพื่อตรวจสอบสภาพแวดล้อมและดักจับในระบบจำลอง นับว่าเป็นการปรับปรุงขั้นสูงของกลุ่มแฮกเกอร์ในยุคนี้ ซึ่งผู้ใช้งานธรรมดาที่ไม่รู้จักเรื่องเหล่านี้ยากที่จะป้องกันได้หากไม่มีความรู้และเครื่องมือที่เหมาะสม สุดท้าย การเข้าใจและตื่นตัวเกี่ยวกับกลเม็ดใหม่ ๆ ของมัลแวร์เช่น CrashFix และ ModeloRAT จะช่วยลดความเสี่ยงที่จะตกเป็นเหยื่อได้มากขึ้น ขอแนะนำให้ทุกคนแชร์ข้อมูลเกี่ยวกับภัยเหล่านี้และอัปเดตความรู้กับทีมไอทีหรือผู้เชี่ยวชาญอย่างสม่ำเสมอ เพื่อให้สามารถรับมือได้ทันกับเทคนิคใหม่ๆ ที่เกิดขึ้นอย่างต่อเนื่อง

Related posts

DARK PSYCHOLOGY 101 👁️‍🗨️🔮
#books you may want to add to your #library 🙏🏾🙏🏾🙏🏾
Alchemist Godbody

Alchemist Godbody

524 likes

Police Save Little Girl After Terrifying Escape From Dangerous Mother #cops #bodycam
Jaynelle

Jaynelle

149 likes

You upgraded your vocabulary and your life changed
Words are energy. If you speak like a victim, you become one. If you speak like a CEO, people treat you like one. 💼 I used to use "weak language" to be polite. I thought "Sorry" meant "Nice". I was wrong. It just made me look unsure. Here is how to "Sound Expensive"
Emily | Mindset & Growth

Emily | Mindset & Growth

49 likes

Paige Gilson

Paige Gilson

0 likes

#cars #truck #bedliner #unmasking
Jimbo Slice

Jimbo Slice

324 likes

Unmasking the Lies, Embracing the Truth
🌹 Read this if you’ve ever felt like you were “too much. For years, many of us were told to shrink, silence our voices, and sacrifice our joy just to be “chosen.” But the truth is—real love doesn’t demand your brokenness, it embraces your wholeness. 💎 Sis, you are not too much. You are enoug
keepingupwithjen

keepingupwithjen

19 likes

narc facts
#narccist #narctok #narcknowledge #narcmagnet #narc
andrea35reiss

andrea35reiss

1 like

Simple Ways to End Anxiety and Panic Attacks ♥️♥️♥️
#growthjourney #growthmindset #growth #posh #anxious
POSH🌸

POSH🌸

5 likes

#creatorsearchinsights Police Save Little Girl After Terrifying Escape From Dangerous Mother #cops #karma
1875.copsusa

1875.copsusa

2 likes

Ego unmasking
You don’t need an ego death. You need an ego unmasking. Nobody tells you this part… The ego doesn’t die in one dramatic moment. It dissolves every time you: • choose peace over proving • sit with a feeling instead of escaping it • stop explaining yourself to people committed to misunde
PriestessofPresence💫

PriestessofPresence💫

2 likes

Part 1: Entitled Customer Turns Home Depot Trip into Complete Chaos #bodycam #copsoftiktok #cops #copsusa #policeofficer
Copsfemale.com

Copsfemale.com

0 likes

As a neurodivergent woman, I don’t need a crowd. I just need calm. My neurodivergent brain never liked big groups anyway, solitude feels safer. Look, I’m getting outside again during my unmasking journey. 💛 #neurodivergent #actuallyautistic #overstimulatedmom
Nakaa 🩵

Nakaa 🩵

3 likes

your mind is preventing you from getting what
#CapCut #mindsetinmotion #minds #mindsetpower #subconsciousmind
arnoldaustin231

arnoldaustin231

1 like

Unmasking as a Neurodivergent
Unmasking makes your life feel like it’s falling apart, but it’s actually consciously coming together for the first time, brick by brick. This is why I’ve created the fitness community for neurodivergents with longevity fitness goals. The community is called Moving Unmasked, because I want to
Emily | Women’s Fitness

Emily | Women’s Fitness

1 like

I didn’t realize I was unmasking…
until people sta
At first, nothing felt different. I just stopped forcing things. I stopped pretending I understood conversations when I didn’t. I stopped pushing myself to be social when I was overwhelmed. I stopped laughing just to fit in. I thought I was just being more honest. But slowly… things cha
neurodivergentbb

neurodivergentbb

11 likes

Unmasking ADHD in Women and Young Girls
After living undiagnosed with ADHD for 39yrs, Martha explores the reasons girls and women are underdiagnosed and her lived experiences before and after her 2021 diagnosis. Martha Barnard-Rae writes clear, convincing words for exacting humans. As a copywriter and owner of Word Candy, she specia
EasyToDo

EasyToDo

23 likes

Pattern recognition
Eddie Morris

Eddie Morris

0 likes

Day 3 Unmasking as a Neurodivergent with CPTSD
#UnmaskingChallenge #InnerChildHealing #NeurodivergentVoices #CPTSDRecovery #HealingJourney #BreakingCycles #TraumaRecovery #ResilientSoul #YouAreMoreThanEnough
YAMTE Always

YAMTE Always

1 like

Over the years people have asked me what the “secret” to success is. There have even been times where people have thought I’m literally hiding the “secret sauce”. It’s not the strategy and it’s not some top secret algorithm hack I’m keeping to myself. It’s identity work. It’s mastering the
saleswithjess

saleswithjess

1 like

PODCAST ‘The Actualising Woman’ ADHD + ASD
PODCAST ‘The Actualising Woman’ Late AuDHD Diagnosis & Breakdown. Journey Towards Actualisation. APPLE, SPOTIFY #LateDiagnosed #AuDHD #Unmasking #ASDdiagnosis #ADHD
PODCAST for ADHD / ASD -ers

PODCAST for ADHD / ASD -ers

11 likes

Let me reintroduce myself....
LetsGlowKimber

LetsGlowKimber

2 likes

🧿🪬OkieBerry🪬 🧿

🧿🪬OkieBerry🪬 🧿

1 like

Autism
#autism #read #book #learn
Daily Dose of Inspo

Daily Dose of Inspo

44 likes

Is the shirtless man Yunho??
He hasn't been working out for nothing .. I don't think we are ready for the unmasking. #yunho #ateez #atiny #ateezatiny
Tiff_in_STL

Tiff_in_STL

1 like

#unmasking #paintingreveal #art #CapCut
Sol Summers

Sol Summers

1 like

unmasking is vulnerable
#audhd #adhd #masking #embracevulnerability #neurospicy
Ren

Ren

14 likes

Found Out My Boss Was Doing VOODOO on ME! 😱😱
The fist part (fully) is on Substack. I’ll be updating every two days more of the True story. Follow along maybe I’ll reveal my identity! Link in bio #lemon8dairy #HiLemon8 #spiritual #witchcraft #voodoo
Lady Seven

Lady Seven

0 likes

Thomas Koberstein

Thomas Koberstein

0 likes

Unmasking my ADHD
I started masking My ADHD when I entered elementary school. When I was younger in pre-k and kindergarten I was able to be myself without much repercussions. Once I started hitting the years where academics was the focus, I was always in trouble for being “too loud” or “too chatty” or not organized
Danielle

Danielle

30 likes

plants that were rare in 2020 but not so much now
If you collected houseplants back in 2020, you probably remember how expensive some plants used to be. Because of the pandemic, many people started collecting houseplants to connect with nature after being inside for so long and to bring happiness in uncertain times. This ‘houseplant boom’ led to i
catherine

catherine

13 likes

Neuro-spicy by @neurospiritual
It's ok to take care of you, you deserve care. #neurospicy #mentalhealing #wellness
Channel Heed

Channel Heed

1522 likes

UNMASKING MLMS PT 2: A LEGAL SCAM
We’re back with part 2 of #unmaskingmlms ! This series exposes the dangers of #MLM businesses. This isn’t meant to shame anyone in an MLM. They are predatory and so many people, especially #sahm . This is simply to raise awareness. Part 2 is how MLMs aren’t illegal, per a 1970s FTC ruling (s
💕 Andrea 💕

💕 Andrea 💕

7 likes

– PT 15: Unmasking Ego, Embracing Truth🅿️💯🙏🏾
Today On CODES 2 LIVE BY with STFUJAs – PT 15: Unmasking Ego, Embracing Truth Raw, streetwise self-improvement that blends motivational grit with spiritual insight—perfect for hustlers who demand authenticity. “Drop the ego, face discomfort, and discover your true worth. These five codes cha
J A s 👸🏾• MESSENGER OF L💌VE

J A s 👸🏾• MESSENGER OF L💌VE

3 likes

Unmasking troubles 🤣
Hahahahahahahaha....ahhhhhh 🫠 . . . . #unmaskedautistic #unmasking #healing #trauma #neurodivergent #relatable #relate #skit #audhd #autism #adhd #tempyvixen
TempyVixen

TempyVixen

4 likes

recording these videos in one take is forcing me to have more self trust in what needs to be said. But also in knowing that the words that come to mind are exactly what I am supposed to say in the moment ✨ I hope you enjoy this stream of consciousness as much as I enjoyed sharing. And for me
Lindsey

Lindsey

1 like

Signs She’s Fake Interested
Unmasking the signs of fake interest in dating! 💔✨ If you want to know whether she’s genuinely into you or just playing games, check out my latest video on YouTube at DreamCarQueen. Your heart deserves the truth! #lovegames #singlelife #formen #datingstruggles
dreamcarqueen

dreamcarqueen

2 likes

Special Interest Polly!
Merry Christmas to me!
UnmaskingwithWhitney

UnmaskingwithWhitney

0 likes

🚩IS GOD’S WAY EVER A*USIVE⁉️
🧠As a psychologist, I'm unmasking the Omnipotent Defense in the TD McNutt case. When a leader uses their title to bypass boundaries, it isn't discipline, it's coercive control. #Psychology #Lemon8Diary #SpiritualAbuse #empatheticcommunication #NarcissistExposed
Dr. Jules the Psychologist

Dr. Jules the Psychologist

1 like

Unmasking Autism = Healing ❤️‍🩹
#autism #nostalgia #autisticgirl #stimming #neurodivergent
Rachel 🌈♾️

Rachel 🌈♾️

5 likes

See more