logo

Low-level cybercriminals are pouncing on CrowdStrike-connected outage

ID: 758ebac8-87f1-5883-b352-aac953ac6bc0

STIX ID: report--758ebac8-87f1-5883-b352-aac953ac6bc0

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2024-07-23

Date Updated: 2026-04-21

Author: AJ Vicens

...
...

Following a faulty CrowdStrike Falcon update that disabled millions of Windows devices, multiple malicious actors capitalized on the outage: phishing lures and CrowdStrike-themed files delivered information stealers (Daolpu, Connecio), HijackLoader-based installers, and at least one wiper claimed by the hacktivist persona “Handala Hack.” Researchers observed thousands of newly registered CrowdStrike-like domains and numerous bogus certificates; vendors and national cybersecurity agencies reported active exploitation and coordinated mitigation efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.