Campaign record
ModeloRAT via a fake CrashFix popup
ModeloRAT delivered after a fake ad-blocker extension crashes the victim's browser
- Status as last assessed
- Active
- First seen
- Unrecorded
- Last seen
- Unrecorded
- Indicators
- 20
- Sources
- 1
- Targets
- Windows
- Fake error dialog
- ModeloRAT
- Malicious browser extension
- Malvertising
Original research
- Microsoft Threat Intelligence2026-02-05Vendor researchFirst account
New Clickfix variant ‘CrashFix’ deploying Python Remote Access Trojan
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Microsoft Defender Experts reported this activity on 5 February 2026, having first identified it the month before, and gave the variant the name CrashFix. The chain starts with an advertisement shown to people looking for an ad blocker; the ad leads to the official Chrome Web Store and an extension posing as uBlock Origin Lite. After a delay the extension traps the browser in a loop and shows a counterfeit repair warning, which tells the visitor to run a pasted command in the Windows dialog box. That command copies the built-in finger utility under another name to pull obfuscated PowerShell from an attacker address. On a domain-joined machine the script fetched a portable Python bundle and a Python remote access trojan Microsoft names ModeloRAT, which beacons over plain HTTP, persists through a Run key, and pulled a further payload from Dropbox.
Overlap with other campaigns
We compared the 20 indicators in this record — covering 2 distinct registrable domains — against the 43 other published campaigns in this corpus.
Ricardo marketplace lure in German
2026-08-07No indicator is shared, but the two records use the same registrable domains.
Shared registrable domain (1)
- domain, shown defanged for safety: dropbox dot com
A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| Windows Run dialog | 23 of 4452% | T1204.004 |
| PowerShell | 19 of 4443% | T1059.001 |
| Clipboard injection | 15 of 4434% | T1204.004 |
| finger.exe payload retrieval | 1 of 442% | — |
No other campaign on record combines them. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
20 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “ModeloRAT via a fake CrashFix popup”, campaign ID 7d88b9bf, retrieved 2026-08-29, snapshot fb0eed7.
https://clickfixreport.com/campaigns/7d88b9bf/crashfix-python-rat-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.