HomeYoutubeCrowdStrike: Fake updates distribute malware

CrowdStrike: Fake updates distribute malware

Cybercriminals are exploiting a massive IT outage resulting from a faulty CrowdStrike update, affecting Windows PCs and Microsoft services. Hackers are using the CrowdStrike situation to target companies with data wiper malware and remote access tools.

According to reports from Windows 10 users, the update resulted in crashes, Blue Screen of Death (BSOD), and inability to restart. Users and businesses around the world also experienced issues and outages in Microsoft 365 and Azure services.

Microsoft estimated that the incident, described as one of the worst IT outages in history, affected 8.5 million computers worldwide.

See also: CrowdStrike actively assists affected customers

CrowdStrike hackers malware updates

Businesses, banks, hospitals and airlines were the hardest hit. As businesses struggle to restore Windows systems, researchers and government agencies have spotted an increase in phishing emailstrying to exploit the situation.

In an update, CrowdStrike says it is “actively assisting customers” who were affected. The company advises customers to verify that they are communicating with legitimate representatives through official channels.

"I urge all users to remain vigilant and ensure they are communicating with official CrowdStrike representatives. Our blog and technical support will continue to be the official channels for the latest updates," said George Kurtz, CEO of CrowdStrike.

The UK 's National Cyber ​​Security Centre has also detected an increase in phishing emails using the CrowdStrike outage as bait.

Automated malware analysis platform, AnyRun, has observed “an increase in CrowdStrike impersonation attempts.”

See also: CrowdStrike: Many devices are working again after the “blackout”

Hackers distribute malware as CrowdStrike fixes or updates

On Saturday, cybersecurity researcher g0njxa first reported a malware distribution campaign targeting customers of Spanish bank BBVA, offering a fake update to fix issues caused by a previous CrowdStrike update. In reality, it was installing the Remcos RAT on victims' devices.

CrowdStrike: Fake updates distribute malware

The fake hotfix was promoted via a phishing, portalintranetgrupobbva[.]com, which pretended to be a BBVA Intranet portal. The malicious file contains instructions informing employees and partners to install the update. This is supposed to avoid errors when connecting to the company's internal network.

"Mandatory update to avoid connection and synchronization errors with the company's internal network," reads the "instructions.txt" file in Spanish.

AnyRun said the fake hotfix delivers HijackLoader, which then installs the Remcos on the infected system.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Are METRO AEBE and My Market affected by the CrowdStrike blackout?

In another warning, AnyRun announced that attackers are distributing a data wiper under the guise of delivering an update from CrowdStrike. Behind this campaign, the pro-Iranian hacktivist Handala, which told X that it impersonated CrowdStrike in phishing emails to target Israeli companies with the data wiper.

The attackers impersonated CrowdStrike by sending emails from the domain “crowdstrike.com.vc,” telling customers that a tool had been created to restore Windows online. The emails included a PDF containing further instructions on how to perform the fake update, as well as a link to download a malicious ZIP file from a file hosting service. This zip file contained an executable file named “Crowdstrike.exe.”

Once the fake CrowdStrike update is executed, the data wiper is extracted to a folder under %Temp% and launched to destroy data stored on the device.

The above shows that users should be very careful with the emails, messages and calls they receive and avoid clicking on suspicious files.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS