Security Risk Advisors
TIGR Threat Bulletin on CrowdStrike Outage Exploitation
Pages
1
Time to read
1 min
Publication
Language
English
Pages
1
Time to read
1 min
Publication
Language
English
This technical report addresses the phishing campaigns launched by threat actors in response to the recent CrowdStrike outage. It outlines the nature of these campaigns, which involve the registration of malicious domains that impersonate legitimate support sites. The report details the tactics employed by attackers, including the use of emails claiming to be from CrowdStrike Support, targeting individuals and organizations alike. It emphasizes the risks associated with installing malicious patches or following fraudulent instructions, which could lead to data theft and unauthorized access to systems. Recommendations are provided for organizations to mitigate these threats, including the necessity of verifying the legitimacy of patches and instructions from official CrowdStrike sources. Additionally, the report suggests utilizing DNS services to block access to newly registered malicious domains. The document serves as a critical resource for organizations relying on CrowdStrike Falcon Sensor products, particularly those operating on Windows machines.