Cybercriminals Exploit CrowdStrike Falcon Update

by Jul 30, 2024Business, mfa, password manager, Ransomware, security, software, spam, Technology0 comments

Overview

Five days after a faulty update to CrowdStrike’s Falcon security software crippled millions of Windows computers globally, cybercriminals and hacktivist personas have seized the opportunity to launch new attacks. They are exploiting the chaos with newly registered domains, malware-laden files disguised with CrowdStrike-themed names, and at least one notable instance of data-wiping malware.


Exploitation and Malicious Activities

CrowdStrike has reported several instances of criminal activities linked to the update incident. These include:

  • Malware Infiltrations: A Word document embedded with the Daolpu information stealer and a zip file targeting Latin American CrowdStrike customers with HijackLoader malware. The latter is typically used to deliver additional malware packages. There’s also a Python-based information stealer tracked as “Connecio.”
  • Phishing Attacks: A sophisticated phishing email campaign purporting to provide remediation for the Falcon issue. The email contains a PDF that delivers a zip file laced with wiper malware, according to sandbox company ANY.RUN. This attack has been one of the most advanced outage-related exploits so far.
  • Hacktivist Involvement: The pro-Palestinian hacktivist persona “Handala Hack” claimed responsibility for the wiper attack mentioned by ANY.RUN. They alleged, without evidence, to have targeted “thousands of Zionist organizations” in a June 21 Telegram post. Handala Hack has a history of executing wiper attacks on both Windows and Linux systems and engaging in hack-and-leak operations.

Expert Insights

Tom Hegel, Principal Threat Researcher with SentinelLabs, highlighted Handala Hack’s broad targeting scope and suggested potential Iranian backing, commonly active in the Middle East since last year. The complete scope of these CrowdStrike-themed intrusions remains unclear, but the attacker has publicly claimed to have dozens of victims.


CrowdStrike’s Response

CrowdStrike has yet to comment on the threats exploiting the situation. However, CrowdStrike founder and CEO George Kurtz acknowledged the potential for adversaries and bad actors to exploit such events, urging customers to engage with official CrowdStrike representatives.


Domain Registrations and Certificate Issues

Jose Enrique Hernandez, Threat Research Director at Splunk, identified over 2,000 CrowdStrike-related domains registered in the past week, with many appearing suspicious. James Spiteri, a Director of Product Management with Elastic, documented more than 141 certificates for seemingly bogus CrowdStrike domains, a number that increased to 193 by mid-afternoon Tuesday.


Impact and Recovery

The malicious activities come as CrowdStrike customers continue to recover from the outage, which Microsoft estimates affected at least 8.5 million Windows devices. Delta Airlines, for instance, is under investigation by the Transportation Department after canceling thousands of flights due to the outage.

A Cybersecurity and Infrastructure Security Agency (CISA) spokesperson confirmed collaboration with government and industry partners to mitigate the impact of the global IT outage. Although there was no specific response regarding malicious activities targeting federal networks, technical issues were reported at multiple federal agencies.

CISA previously acknowledged awareness of malicious activity connected to the event, in line with statements from cybersecurity officials in the U.K., Australia, and Canada.


Final Thoughts

The CrowdStrike Falcon update mishap has highlighted the vulnerability of critical security infrastructure and the opportunistic nature of cybercriminals. As the situation evolves, it underscores the importance of robust cybersecurity measures and the need for vigilant, timely responses to mitigate the impact of such incidents.

PTSI Editorial Team

Support Line: Phone: +1 646-535-HELP (4357) Email: helpdesk@progressny.com Support web: helpdesk.progressny.com