logo

CrowdStrike 'Updates' Deliver Malware & More as Attacks Snowball

ID: efe44d40-46ac-54d3-b088-d72322b381b0

STIX ID: report--efe44d40-46ac-54d3-b088-d72322b381b0

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-07-25

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Following a CrowdStrike outage, cybercriminals rapidly launched targeted phishing and typosquatting campaigns against affected customers — registering thousands of spoof domains and distributing malicious artifacts (including a ZIP containing HijackLoader that loaded the RemCos RAT and a separate wiper claimed by the hacktivist group Handala). Attacks are more targeted and higher-volume than typical news-driven scams, leveraging fake hotfixes, malicious attachments, and support impersonation to regain access or destroy data; defenders are advised to use blocklists, protective DNS, and only rely on official CrowdStrike support channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.