Fake ad blocker extension crashes the browser for ClickFix attacks
A new malvertising campaign employs a fake ad blocker extension, NexShield, to crash browsers and facilitate ClickFix attacks. This attack delivers a Python-based remote access tool, ModeloRAT, which can execute commands and modify system settings, highlighting the importance of cautious extension installations.