Beware of fake CrowdStrike domains pumping out Lumma infostealing malware
ID: d3d9861c-c51a-5ed0-a9c0-a4a5375310d6
STIX ID: report--d3d9861c-c51a-5ed0-a9c0-a4a5375310d6
Feed Name: The Register (Security)
CrowdStrike has been impersonated in a phishing campaign that lures Windows users to download a purported recovery tool from a malicious domain (crowdstrike-office365.com). The archive contains a malicious MSI that drops a multi-stage loader (self-extracting RAR -> NSIS/AutoIt) which executes shellcode and deploys the Lumma infostealer; the campaign uses social-engineering (email + follow-up phone calls), targets corporate networks, and shares infrastructure with earlier Lumma distributions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
