logo

Fake CrowdStrike repair manual pushes new infostealer malware

ID: 277d5894-6748-5860-b6f5-ee9b8b75db4d

STIX ID: report--277d5894-6748-5860-b6f5-ee9b8b75db4d

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-07-23

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

CrowdStrike warnings detail a phishing campaign that distributes the Daolpu info-stealer via a malicious Word document titled 'New_Recovery_Tool_to_help_with_CrowdStrike_issue_impacting_Windows.docm' claiming to fix recent CrowdStrike Falcon outages; macros download a base64-encoded DLL dropped to %TMP%\mscorsvc.dll, decoded with certutil, executed to harvest browser credentials and cookies from Chrome, Edge, Firefox and Cốc Cốc, and exfiltrate them to http://172.104.160.126:5000/Uploadss, with CrowdStrike providing YARA rules and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.