CrowdStrike Falcon Outage Exploited for Social Engineering
ID: abd9ea2f-d546-50e2-92d3-efb80d0b07b6
STIX ID: report--abd9ea2f-d546-50e2-92d3-efb80d0b07b6
Feed Name: CISecurity.org Insights Blog
CIS CTI reports that following the July 19, 2024 CrowdStrike Falcon content update outage, threat actors launched opportunistic social-engineering campaigns leveraging typosquatted CrowdStrike-themed domains and a fake “Crowdstrike-hotfix.zip” to deliver HijackLoader and RemCos RAT; the report provides extensive IOCs (domains, hashes, and a C2), maps activity to MITRE ATT&CK (e.g., phishing, user execution), and urges SLTT entities to use official vendor guidance and monitor shared indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
