The Scam Strikes Back: Exploiting the CrowdStrike Outage
ID: 942aad39-72c4-51f5-b456-a6833b0d2b87
STIX ID: report--942aad39-72c4-51f5-b456-a6833b0d2b87
Feed Name: McAfee Labs Blog
Following a CrowdStrike Falcon outage, attackers and scammers rapidly deployed multiple malicious campaigns impersonating CrowdStrike remediation tools: document-macro stealer (downloads via curl/certutil, infostealer DLL), PDF-delivered wipers, and Remcos RAT delivered through zip/Hijack Loader; numerous spoofed domains and cryptocurrency wallets were registered and active. The report includes infection chains, sample malware hashes, a large list of malicious or suspicious domains, and advises consumer vigilance while pointing enterprises to CrowdStrike’s official remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
