Cybersecurity Agencies Report Surge in Phishing After CrowdStrike Outage

28 Jul 2024

In the wake of last week’s CrowdStrike outage, a surge of cybercriminal activity has emerged, leveraging the chaos to execute social engineering attacks against the security vendor’s clientele. The incident, which disrupted air travel, closed retail operations, and halted medical services, has drawn the attention of national cybersecurity agencies across the US, UK, Canada, and Australia. These agencies have reported a notable uptick in phishing attempts, a trend not uncommon following significant news events. However, BforeAI CEO Luigi Lenguito highlights that the scale and precision of these post-CrowdStrike attacks are unprecedented.

For context, Lenguito notes that during a previous incident involving a high-profile figure, there was a spike of around 200 related cyber threats on the first day, which then stabilized to approximately 40 to 50 daily threats. In stark contrast, the current situation has seen a dramatic increase, with daily attacks ranging from 150 to 300. “This is not the normal volume for news-related attacks,” he asserts.

Profile of a CrowdStrike-Themed Scam

Lenguito elaborates on the modus operandi of these CrowdStrike-themed phishing attacks, explaining that they are particularly insidious due to their targeted nature. “We have these large corporations’ users who are lost, because their computers cannot connect to the mothership, and now they’re trying to get connected. It’s a perfect opportunity for cybercriminals to infiltrate these networks,” he explains.

Unlike broader attacks, these scams are directed at organizations directly impacted by the outage, and the potential victims tend to possess a higher level of technical expertise and cybersecurity awareness. To gain access, attackers have been impersonating the company itself, offering technical support, or even posing as competing firms with enticing “solutions.”

The evidence of this malicious activity is reflected in the proliferation of phishing and typosquatting domains registered in recent days, such as crowdstrikefix[.]com, crowdstrikeupdate[.]com, and www.microsoftcrowdstrike[.]com. One diligent security researcher has identified over 2,000 such domains that have surfaced thus far.

These domains may serve as conduits for malware distribution, exemplified by a ZIP file masquerading as a hotfix that was uploaded to a malware scanning service last weekend. This ZIP file contained HijackLoader, which subsequently loaded the RemCos RAT. The initial report of this file originated from Mexico, with Spanish-language filenames suggesting a targeted campaign against CrowdStrike customers in Latin America.

In another instance, attackers disseminated a CrowdStrike-themed phishing email accompanied by a poorly designed PDF attachment. This PDF contained a link to download a ZIP file that housed an executable. Upon execution, the file prompted the victim for permission to install an update, which turned out to be a wiper. The hacktivist group “Handala” claimed responsibility, asserting that numerous Israeli organizations had suffered significant data losses as a result.

Regardless of the methods employed, Lenguito advises organizations to bolster their defenses by utilizing blocklists, protective DNS tools, and ensuring that they seek technical support exclusively from CrowdStrike’s official channels. Alternatively, he suggests that patience may be a virtue, as these campaigns typically last between two to three weeks. “We’re still early, right? We’ll probably see it taper over the coming weeks,” he concludes.

Why is CrowdStrike stock dropping today Reddit?

The drop in CrowdStrike's stock today as discussed on Reddit could be attributed to various factors such as market rumors, negative sentiment, or broader market sell-off trends. Specific concerns or speculative posts by Reddit users could highlight issues like disappointing earnings, cybersecurity threats, or competitive pressures which could be influencing investor behavior on the platform.

Why is CrowdStrike stock dropping today?

CrowdStrike stock might be dropping today due to a number of reasons including weak earnings reports, negative analyst reviews, broader market declines, or news of increased competition in the cybersecurity sector. External factors such as economic data releases or geopolitical events can also contribute to the decline in stock prices.
uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
5739210
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1033991
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
441408
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
374081
downloads

EggStreme Malware Targeting Philippine Military Identified

Researchers at Bitdefender uncover EggStreme, a novel malware targeting a Philippine military entity, featuring multi-stage espionage tactics and advanced persistence.

Read more

Frosthaven Expands With New Quests and Heroes in Major Updates

Frosthaven, the digital board game adaptation, will introduce new heroes, quests, and storylines in major updates by Snapshot Games. These expansions aim to enhance the gameplay experience as Frosthaven progresses through its Early Access phase on Steam.

Read more

Epic Games Store Offers Free Games Including Ghostrunner 2

Epic Games Store is offering Free Games for a limited time, including Ghostrunner 2. These titles are available until 4pm BST on 18 September 2025, allowing players to explore diverse gaming experiences from a cyberpunk future to strategic tribal battles.

Read more

Strategic Tips for Conquering Beastfly in Pharloom

Learn effective strategies to tackle Beastfly in Pharloom with the right preparation and combat tactics for both the Hunter's March and Far Fields encounters.

Read more

Ghostrunner 2 Now Free on Epic Games Store for Limited Time

Ghostrunner 2, a fast-paced cyberpunk action game, is currently free on the Epic Games Store. Experience the enhanced combat, upgraded katana, and expansive new settings in this highly-rated sequel, available until September 18 alongside Monument Valley 2 and The Battle of Polytopia.

Read more

Microsoft Faces Scrutiny Over Security and Ransomware Threats

Sen. Wyden urges FTC probe into Microsoft's role in ransomware, citing inadequate cybersecurity. Wyden calls for stronger security measures for legacy encryptions like RC4.

Read more

Microsoft Releases Windows 11 25H2 ISOs for Testers

Microsoft has released ISO files for Windows 11 25H2, allowing testers a clean installation process before the update's full release. The update maintains core system components intact while offering significant internal improvements and is expected to be generally available in October.

Read more

Hell Let Loose Vietnam Offers Asymmetric Warfare Experience

Hell Let Loose Vietnam surprises with its setting shift. This sequel introduces asymmetric mechanics, offering unique strategies for players. Set during the Vietnam War, it promises an intense, immersive combat experience, expanding on the series' existing foundations ahead of its 2026 release.

Read more

Nano11 Launches: Minimizing Windows 11 Installation Size

NTDEV introduces Nano11, a PowerShell tool trimming Windows 11 ISOs, achieving up to 3.5 times size reduction. Designed for experimental use, it streamlines installations by removing non-essential components.

Read more

Helmets Now Available in Latest Space Marine 2 Update

Saber Interactive releases fan-favorite helmets in Space Marine 2, including the plain Mark 8, with patch 10.1, available in the store. The update also resolves gameplay bugs, enhancing the gaming experience.

Read more