logo

Phishing Campaigns Continue To Exploit CrowdStrike Outage

ID: 16cd2d9e-9ace-5f45-959d-23005b9f20e9

STIX ID: report--16cd2d9e-9ace-5f45-959d-23005b9f20e9

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2024-07-26

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Threat actors are exploiting a global CrowdStrike content-update outage by registering impersonating domains, sending phishing emails and calls claiming to be CrowdStrike support, and distributing a malicious file named "crowdstrike-hotfix.zip" that installs the RemCos RAT; CISA, NCSC, ASD and security vendors have issued warnings and observed Spanish-language targeting in Latin America and other opportunistic scams tied to the outage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.