Recent threat activity has highlighted two distinct user-targeted campaigns: mass spam sent from legitimate Zendesk domains and a browser-crash social-engineering chain delivering malware. Multiple users reported receiving hundreds of emails originating from real companies’ Zendesk helpdesk instances (including brands such as Live Nation, Capcom, and Tinder), with many messages bypassing common spam filters; the lures included bogus legal notices intended to drive credential theft, initial access, or payment. Zendesk has previously warned about attackers abusing its platform for relay spam, and reporting indicated the current wave was not tied to a Zendesk breach or a specific software vulnerability.
Separately, Huntress reported a more sophisticated ClickFix-style operation dubbed “CrashFix” that uses a malicious Chrome Web Store extension (NexShield, masquerading as uBlock Origin Lite) to intentionally crash the victim’s browser and then present a fake “fix” prompt that advances the infection chain. The campaign was attributed to KongTuke and culminates in delivery of a Python-based RAT (ModeloRAT), with domain-joined systems receiving specially tailored backdoor payloads—raising risk for enterprise environments where browser-based workflows are prevalent. Other items in the set were general-interest content (enterprise browser product comparison, a cyberattacks timeline roundup, and an acquisition announcement) and did not provide additional, specific reporting on these two active campaigns.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Alongside its report, Huntress released indicators of compromise and advised defenders to monitor for suspicious Windows utility use, malicious browser extensions, Registry Run-key persistence, and Python spawning hidden PowerShell.
In the CrashFix campaign, users searching for an ad blocker were lured via malicious ads to install "NexShield," a Chrome Web Store extension posing as uBlock Origin Lite. After forcing a browser crash, the extension led victims to execute a PowerShell command that profiled the host and delivered the newly seen Python-based ModeloRAT to domain-joined Windows systems.
Huntress Labs reported a new "CrashFix" variant of the ClickFix scam attributed to the threat actor it tracks as KongTuke. The campaign used a fake Chrome extension and browser-crash ruse to trick victims into running a malicious repair command.
As reports of the spam campaign spread, Zendesk's security team was said to be investigating whether the activity stemmed from the previously documented relay-spam issue or a different abuse path, such as help-desk workflow manipulation or configuration weaknesses.
ElevenLabs publicly apologized for a mass spam attack affecting its email ticketing system and said it was working with Zendesk to resolve the issue. The statement linked a named victim organization to the broader Zendesk abuse activity.
By January 2026, multiple users reported a wave of spam emails sent from Zendesk domains tied to real companies, with themes such as bogus lawsuits and legal or government notices. The messages often bypassed spam filters and appeared aimed at credential theft, initial access, or fraud.
Before the January 2026 spam wave, Zendesk published an advisory warning that attackers could send spam through Zendesk using relay-spam techniques involving misconfigured email servers and recommended mitigations for customers.
In November 2025, ReliaQuest reported that actors linked to "Scattered Lapsus$ Hunters" may have been preparing a campaign against Zendesk environments using typosquatted and phishing login pages to harvest credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.