CrowdStrike Outage: Script, Phishing, and Social Engineering Attacks
ID: d518848d-c88d-5004-a13c-ac422eaa4637
STIX ID: report--d518848d-c88d-5004-a13c-ac422eaa4637
Feed Name: ReliaQuest Blog
**Executive Summary:** On July 19, 2024 a CrowdStrike Falcon update caused widespread Windows BSODs, and adversaries rapidly exploited the outage by distributing malicious recovery files (including a ZIP deploying Remcos RAT and macro-enabled Word docs) and registering impersonating domains to conduct phishing and malware delivery; the report provides IoCs (hashes, an IP, many domains), remediation guidance from Microsoft and CrowdStrike, and recommendations to verify official sources, avoid running untrusted scripts, and educate users against social engineering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
