HomeSecurityFake CrowdStrike repair manual pushes infostealer Daolpu

Fake CrowdStrike repair manual pushes infostealer Daolpu

CrowdStrike warns that a fake recovery manual for repairing Windows installs a new infostealer called Daolpu.

See also: CrowdStrike CEO called to testify about outage

CrowdStrike infostealer Daolpu

Since Friday, when the CrowdStrike Falcon update caused a global IT outage, threat actors have immediately begun exploiting the incident to push malware via fake patches.

A new campaign, conducted via phishing, pretends to provide instructions on how to use a new Recovery Tool that fixes Windows devices affected by the recent CrowdStrike Falcon bugs.

Once activated on the system, the Daolpu infostealer collects account credentials, browser history , and authentication cookies stored in Chrome, Edge, Firefox , and Cốc Cốc.

The Daolpu infostealer is believed to be spread via phishing emails, which carry an attached document disguised as a Microsoft recovery manual for the problematic CrowdStrike release, named “New_Recovery_Tool_to_help_with_CrowdStrike_issue_impacting_Windows. docm.'

This document is a copy of a support bulletin that provides instructions on using a new remediation tool that automates the removal of the problematic CrowdStrike driver from Windows devices.

See also: CrowdStrike: Fake updates distribute malware

Hackers impersonate cybersecurity companies in phishing callback emails

However, this document contains macros that, when enabled, download a base64 encoded DDL file from an external resource and drop it into “%TMP%mscorsvc.dll“.

The macros then use Windows certutil to decode the DLL, which is executed to launch the Daolpu stealer on the compromised device

Daolpu terminates all running Chrome processes and then attempts to collect login data and cookies stored in Chrome, Edge, Firefox, and other Chromium.

The stolen data is temporarily stored in '%TMP%\result.txt' and then deleted after being sent back to the attackers on the C2 server, using the URL 'http[:]//172.104.160[.]126:5000/Uploadss'.

CrowdStrike urges its customers to follow the advice found on the company's website or other trusted sources only after confirming the authenticity of their communications.

See also: Microsoft: Fix tool to remove CrowdStrike driver

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Infostealer, such as Daolpu, pushed via the fake CrowdStrike fix manual, is a type of malware designed to extract sensitive data from a victim’s system without their knowledge. Typically targeting personal information such as passwords, banking details and credit card numbers, these malicious programs can operate covertly, often using keyloggers or URL sniffers to capture data as it is entered. Once the information is gathered, it may be transmitted to a remote server controlled by cybercriminals, who can then exploit it for a variety of illegal purposes, including identity theft and financial fraud. Users can protect themselves by using strong security measures such as antivirus software and regular system updates, along with safe browsing habits.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS