logo

Fake CrowdStrike fixes target companies with malware, data wipers

ID: 942d4de9-8cd2-5f27-be8d-9baaf9265c81

STIX ID: report--942d4de9-8cd2-5f27-be8d-9baaf9265c81

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-07-21

Date Updated: 2026-07-17

Author: Ionut Ilascu

...
...

Threat actors are exploiting CrowdStrike's faulty Windows sensor update outage to send phishing lures and fake 'hotfix' packages that install loaders (HijackLoader) which drop the Remcos RAT, and to distribute a destructive data wiper (claimed by pro‑Iranian group Handala). Campaigns used impersonation (fraudulent domains and emails), malicious ZIP attachments (containing Crowdstrike.exe), and phishing sites (e.g., a fake BBVA intranet) to trick users into running updates, while the underlying CrowdStrike outage disrupted millions of Windows hosts and created a large attack surface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.