Hackers Exploits CrowdStrike Issues to Lauch RemCos Malware on Windows
ID: 44b33f60-5ec8-5c9c-9b9d-76c5636afc07
STIX ID: report--44b33f60-5ec8-5c9c-9b9d-76c5636afc07
Feed Name: cybersecurityNews.com
CrowdStrike reported that a Falcon sensor content update issue was abused by threat actors to distribute a malicious ZIP (crowdstrike-hotfix.zip) targeting Latin America customers; the archive contains a HijackLoader (DLL search-order hijack) and a RemCos payload that contacts C2 at 213.5.130.58:443. The report provides technical details, SHA256 hashes for the ZIP, loader, config and RemCos sample, a list of typosquatting domains, and a Falcon LogScale hunting query for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
