In January 2026, Huntress Senior Security Operations Analyst Tanner Filip observed threat actors using a malicious browser extension to display a fake security warning, claiming the browser had “stopped abnormally” and prompting users to run a “scan” to remediate the threats. Our analysis revealed this campaign is the work of KongTuke, a threat actor we have been tracking since the beginning of 2025. In this latest operation, we identified several new developments: a malicious browser extension called NexShield that impersonates the legitimate uBlock Origin Lite ad blocker, a new ClickFix variant we have dubbed “CrashFix” that intentionally crashes the browser then baits users into running malicious commands, and ModeloRAT, a previously undocumented Python RAT reserved exclusively for domain-joined hosts.

  • cm0002@lemmings.worldOP
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    23 hours ago

    Not sure why you’d want to forward traffic to an instance who has admins that are transphobic and push Russian propaganda but you do you, I can’t stop you :)

    • AmbiguousProps@lemmy.today
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      edit-2
      23 hours ago

      I didn’t just link to ML, but go off! I’m not the one crossposting the content in the first place, I wouldn’t have linked to ML if that wasn’t where you got the post to begin with. Nice of you to bring up transphobia in an argument against a trans person, though!

        • AmbiguousProps@lemmy.today
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          edit-2
          23 hours ago

          I don’t care what transphobes have to say, I’ve heard it all before. At least I don’t crosspost content from the land of transphobes, though! You enjoying having your feed be filled with ML content even though you claim to boycott them?

          • cm0002@lemmings.worldOP
            link
            fedilink
            arrow-up
            1
            ·
            23 hours ago

            Taking content from them, doesn’t support their instance in any way. Upvoting, commenting and posting on comms on their instance does. Which I don’t do and by cross-posting content away onto non.ml comms it reduces their activity bit by bit but revitalizing other similar comms

            • AmbiguousProps@lemmy.today
              link
              fedilink
              arrow-up
              1
              arrow-down
              1
              ·
              23 hours ago

              But by your logic, the built in crosspost functionality is no worse than what I’ve done, right? Since the crosspost links always work, therefore you also linked to ML?

              • cm0002@lemmings.worldOP
                link
                fedilink
                arrow-up
                1
                arrow-down
                1
                ·
                23 hours ago

                They display, in a separate submenu, increasing friction. It’s well known in human behavior/UI design that every additional click for the average user reduces the likelihood they’re just going to click it for no reason

                • AmbiguousProps@lemmy.today
                  link
                  fedilink
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  23 hours ago

                  That’s not really friction, and in fact, on the standard Lemmy UI, it’s not in a submenu at all…it’s just straight up linked under the post title. No extra click required. So what’s the difference?

                  • cm0002@lemmings.worldOP
                    link
                    fedilink
                    arrow-up
                    1
                    arrow-down
                    1
                    ·
                    23 hours ago

                    Well sure, it’s not foolproof, but the vast majority of users are probably not using the default Lemmy UI (because it kinda sucks lol) and instead are using an app or other front end.