CrowdStrike Warns of New Threat Actor Targeting German Customers

26 Jul 2024

CrowdStrike has issued a warning about a new threat actor taking advantage of the Falcon Sensor update incident to distribute suspicious installers aimed at German customers in a highly targeted campaign. The cybersecurity firm detected an unattributed spear-phishing attempt on July 24, 2024, distributing a fake CrowdStrike Crash Reporter installer through a website impersonating a German entity.

The imposter website was created on July 20, following the update crash that affected millions of Windows devices globally. According to CrowdStrike’s Counter Adversary Operations team, the website uses JavaScript to download and deobfuscate the installer, which requires a password to proceed with the malware installation. The spear-phishing page includes a link to a ZIP archive file containing a malicious InnoSetup installer, with the executable code injected into a JavaScript file to evade detection. Users who run the bogus installer are prompted to enter a “Backend-Server” to continue, but the final payload deployed remains unknown.

Phishing Attacks Exploiting CrowdStrike Update Issue

The campaign is believed to be highly targeted due to the password protection and German language used, indicating a focus on German-speaking CrowdStrike customers. The threat actor demonstrates awareness of operational security practices by registering a subdomain under the it[.]com domain and encrypting the installer contents to prevent analysis and attribution.

A phishing domain crowdstrike-office365[.]com hosts rogue archive files containing a Microsoft Installer (MSI) loader that executes the Lumma information stealer. A ZIP file (“CrowdStrike Falcon.zip”) contains a Python-based information stealer known as Connecio, which collects system information and exfiltrates it to SMTP accounts.

CrowdStrike’s CEO George Kurtz announced that 97% of the affected Windows devices are now operational following the global IT outage caused by the update issue. Kurtz expressed regret for the disruption and assured a focused and urgent response to regain trust. Chief Security Officer Shawn Henry also apologized for the incident and pledged to deliver better protection against adversaries.

Bitsight’s Analysis Reveals Traffic Patterns of CrowdStrike Machines

Bitsight’s analysis of CrowdStrike machines across organizations globally highlighted significant traffic spikes and drops before and after the IT outage, prompting further investigation into potential correlations. Security researcher Pedro Umbelino emphasized the need to explore the connection between traffic patterns and the outage to better understand the events.

For more exclusive content, follow us on Twitter and LinkedIn.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508551
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735300
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746711
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
495579
downloads

News and reviews for Desktop Windows

Visio 2021 Professional Now $9.97 Until February 8

Microsoft offers Visio 2021 Professional for $9.97, down from $249, with added templates, until February 8.

Read more

Code Vein Offers Stylish Combat, Discounted Editions

Code Vein captivates with anime-style combat and offers discounted editions. Fast-paced action meets fun builds in this cult classic.

Read more

Microsoft Phases Out RC4 in Kerberos for Windows Security

Microsoft to eliminate RC4 in Kerberos by July 2026, enhancing Windows security.

Read more

Highguard Faces Criticism but Shows Potential for Growth

Highguard, launched with controversy, holds potential despite poor reviews. Offering genre innovation, it aims to evolve against negative feedback.

Read more

PS2Recomp Boosts Native PS2 Games with Recompilation

PS2Recomp, a new tool, promises enhanced native PS2 game ports, sparking interest among developers for PC platforms.

Read more

NVIDIA Introduces RTX Remix Logic for Classic Game Mods

NVIDIA's RTX Remix Logic, launched on 2026-01-27, enables dynamic modding of classic PC games with a no-code node-based interface.

Read more

Windows 11 Update KB5074109 Affects Legacy Modems

The Windows 11 update KB5074109 disrupts modems by removing several legacy drivers, causing connectivity issues for select users.

Read more

Anytype Replaces Notion, Obsidian, and Todoist for Unified Workflow

Anytype consolidates Notion, Obsidian, and Todoist functions, reducing context-switching and improving workflow efficiency.

Read more

ReBlade: Cyberpunk Roguelike Announced by ChillyRoom

ReBlade from ChillyRoom and Spiral Up Games announced for PC: cyberpunk roguelike offers high-speed action in a dystopian setting.

Read more

Artorias Battles Elden Ring Bosses in New Video Showcase

Artorias from Dark Souls faces Elden Ring bosses, demonstrating impressive skills in Fights' YouTube video.

Read more