logo

The Scam Strikes Back: Exploiting the CrowdStrike Outage

ID: 942aad39-72c4-51f5-b456-a6833b0d2b87

STIX ID: report--942aad39-72c4-51f5-b456-a6833b0d2b87

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2024-07-30

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

Following a CrowdStrike Falcon outage, attackers and scammers rapidly deployed multiple malicious campaigns impersonating CrowdStrike remediation tools: document-macro stealer (downloads via curl/certutil, infostealer DLL), PDF-delivered wipers, and Remcos RAT delivered through zip/Hijack Loader; numerous spoofed domains and cryptocurrency wallets were registered and active. The report includes infection chains, sample malware hashes, a large list of malicious or suspicious domains, and advises consumer vigilance while pointing enterprises to CrowdStrike’s official remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.