Cybersecurity Agencies Report Surge in Phishing After CrowdStrike Outage

28 Jul 2024

In the wake of last week’s CrowdStrike outage, a surge of cybercriminal activity has emerged, leveraging the chaos to execute social engineering attacks against the security vendor’s clientele. The incident, which disrupted air travel, closed retail operations, and halted medical services, has drawn the attention of national cybersecurity agencies across the US, UK, Canada, and Australia. These agencies have reported a notable uptick in phishing attempts, a trend not uncommon following significant news events. However, BforeAI CEO Luigi Lenguito highlights that the scale and precision of these post-CrowdStrike attacks are unprecedented.

For context, Lenguito notes that during a previous incident involving a high-profile figure, there was a spike of around 200 related cyber threats on the first day, which then stabilized to approximately 40 to 50 daily threats. In stark contrast, the current situation has seen a dramatic increase, with daily attacks ranging from 150 to 300. “This is not the normal volume for news-related attacks,” he asserts.

Profile of a CrowdStrike-Themed Scam

Lenguito elaborates on the modus operandi of these CrowdStrike-themed phishing attacks, explaining that they are particularly insidious due to their targeted nature. “We have these large corporations’ users who are lost, because their computers cannot connect to the mothership, and now they’re trying to get connected. It’s a perfect opportunity for cybercriminals to infiltrate these networks,” he explains.

Unlike broader attacks, these scams are directed at organizations directly impacted by the outage, and the potential victims tend to possess a higher level of technical expertise and cybersecurity awareness. To gain access, attackers have been impersonating the company itself, offering technical support, or even posing as competing firms with enticing “solutions.”

The evidence of this malicious activity is reflected in the proliferation of phishing and typosquatting domains registered in recent days, such as crowdstrikefix[.]com, crowdstrikeupdate[.]com, and www.microsoftcrowdstrike[.]com. One diligent security researcher has identified over 2,000 such domains that have surfaced thus far.

These domains may serve as conduits for malware distribution, exemplified by a ZIP file masquerading as a hotfix that was uploaded to a malware scanning service last weekend. This ZIP file contained HijackLoader, which subsequently loaded the RemCos RAT. The initial report of this file originated from Mexico, with Spanish-language filenames suggesting a targeted campaign against CrowdStrike customers in Latin America.

In another instance, attackers disseminated a CrowdStrike-themed phishing email accompanied by a poorly designed PDF attachment. This PDF contained a link to download a ZIP file that housed an executable. Upon execution, the file prompted the victim for permission to install an update, which turned out to be a wiper. The hacktivist group “Handala” claimed responsibility, asserting that numerous Israeli organizations had suffered significant data losses as a result.

Regardless of the methods employed, Lenguito advises organizations to bolster their defenses by utilizing blocklists, protective DNS tools, and ensuring that they seek technical support exclusively from CrowdStrike’s official channels. Alternatively, he suggests that patience may be a virtue, as these campaigns typically last between two to three weeks. “We’re still early, right? We’ll probably see it taper over the coming weeks,” he concludes.

Why is CrowdStrike stock dropping today Reddit?

The drop in CrowdStrike's stock today as discussed on Reddit could be attributed to various factors such as market rumors, negative sentiment, or broader market sell-off trends. Specific concerns or speculative posts by Reddit users could highlight issues like disappointing earnings, cybersecurity threats, or competitive pressures which could be influencing investor behavior on the platform.

Why is CrowdStrike stock dropping today?

CrowdStrike stock might be dropping today due to a number of reasons including weak earnings reports, negative analyst reviews, broader market declines, or news of increased competition in the cybersecurity sector. External factors such as economic data releases or geopolitical events can also contribute to the decline in stock prices.
uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
5136472
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
874052
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
425688
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
327351
downloads

Microsoft's Potential Handheld Gaming Plans Spark Interest

Speculation grows over a Microsoft device as a potential handheld competitor to the Steam Deck, potentially unveiled at the Xbox Games Showcase.

Read more

Hellslave RPG Available Free on Steam For Limited Time

The dark fantasy RPG Hellslave is now free on Steam, as its sequel approaches. Experience this dungeon-crawler and retain it in your library forever. Claim it by June 16.

Read more

Foxtail Unveils Hidden Gem from Comiket 81 in Gaming History

A mysterious disc titled Action RPG (Temp) C81 Demo Version reveals a rarely seen game from Comiket 81 in 2011, featuring unique stamina-based combat. The demo offers a glimpse into a creative era of RPGs, thanks to the dedicated work of developer Foxtail.

Read more

IO Interactive Unveils New James Bond Game: First Light

IO Interactive announces 007 First Light, a new video game featuring an original James Bond origin story. Players will earn their 00 status in this immersive gaming experience crafted for a fresh perspective within the Bond series.

Read more

Anvil Empires Aims to Revolutionize Medieval RTS Gaming

Anvil Empires, a medieval RTS game inspired by Age of Empires 2, offers a large-scale playtest. It combines classic strategy mechanics with MMO elements, allowing up to 1,000 players per server. The focus is on logistics and teamwork.

Read more

Atomic Heart Game Offers Up to 71% Off Sale This Year

Atomic Heart, a distinctive shooter set in a robot-dystopia, is on sale with a 71% discount. Experience the narrative of rebellion against an authoritarian regime as P-3. With elemental powers and melee combat, it promises a unique adventure at $21.09 / £15.49.

Read more

IO Interactive Reveals James Bond Game 007 First Light

IO Interactive announces 007 First Light, a new James Bond game. The long-awaited origin story adds to the Bond franchise's gaming legacy. Fans eagerly await the full reveal, marking IO Interactive's first major step since 2020.

Read more

Nightreign Patch Improves Gameplay for Singleplayer Mode

The Nightreign patch adds auto-resurrect and boosts levelling, addressing challenges in singleplayer mode. Players now experience improved balance and performance, aligning with FromSoftware's commitment to refining gameplay.

Read more

Elden Ring Patch Enhances Solo Gameplay Dynamics

Elden Ring receives a solo gameplay boost with the Nightreign patch. The update introduces automatic revival and improved rewards, enhancing gamers' experiences.

Read more

Medal of Honor Game Reimagined with Unreal Engine 5

The classic Medal of Honor Allied Assault is reimagined using Unreal Engine 5, receiving praise from original game designer Nathan Silvers. The remake highlights the enduring legacy of the game, despite the uncertain future of the Medal series.

Read more