Fake CrowdStrike fixes target companies with malware, data wipers
ID: 942d4de9-8cd2-5f27-be8d-9baaf9265c81
STIX ID: report--942d4de9-8cd2-5f27-be8d-9baaf9265c81
Feed Name: Bleeping Computer
Threat actors are exploiting CrowdStrike's faulty Windows sensor update outage to send phishing lures and fake 'hotfix' packages that install loaders (HijackLoader) which drop the Remcos RAT, and to distribute a destructive data wiper (claimed by pro‑Iranian group Handala). Campaigns used impersonation (fraudulent domains and emails), malicious ZIP attachments (containing Crowdstrike.exe), and phishing sites (e.g., a fake BBVA intranet) to trick users into running updates, while the underlying CrowdStrike outage disrupted millions of Windows hosts and created a large attack surface.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
