Explorer

Govt Agency Warns Of Phishing Attack Campaign Targeting CrowdStrike Users, Know How You Can Protect Yourself

The attackers are also distributing ‘Trojan’ malware by disguising them as recovery tools.

Indian cybersecurity agency, CERT-In, has announced that a phishing attack campaign has attacked the users who were impacted by the recent Microsoft global outage. As per the agency's warning, the attackers are impersonating CrowdStrike support staff to lure people in to cooperate by offering them help with system recovery tools. As per the advisory issued on Saturday, these attack campaigns could “entice an unsuspected user to install unidentified malware, which could lead to sensitive data leakage, system crashes and data leak.”

The systems that were affected during the outage have recovered due to the fixes released by CrowdStrike and Microsoft. Some users have now launched a 'phishing campaign' to target CrowdStrike users and they are leveraging the outage issue to conduct 'malicious' activities. 

ALSO READ | Weekly Tech Wrap: Budget 2024 Makes Smartphones Cheaper, Apple May Produce iPads In Tamil Nadu, More

Modus Operandi

As per the advisory from the CERT-In, the attackers are launching this attack by sending phishing emails. Then they are connecting with CrowdStrike users via call and are posing as CrowdStrike support. They are selling software scripts to these customers by saying that it will automate recovery from the content update issue.

The attackers are also distributing ‘Trojan’ malware by disguising them as recovery tools. This operation is being carried out so smoothly that it can easily entice any unsuspected user to install unidentified malware. Once they install it, it can easily lead to sensitive data leakage, system crashes and data loss.

How To Safeguard Yourself Against This Threat

As per the advisory, users and organisations have been asked to configure their firewall rules to block connections against 31 types of URLs such as ‘crowdstrikeoutage[.]info’ and ‘www.crowdstrike0day[.]com’. Users have also been recommended to deploy cyber hygiene practices such as fetching software patch updates from trusted websites and sources, avoiding clicking a document with a link to “.exe”, and being cautious against suspicious phone numbers.

CERT-In also suggested users only click URLs that have clear website domains and they should use safe browsing and filtering tools apart from apt firewalls.

CERT-In added, “Look out for valid encryption certificates by checking for the green lock in the browser’s address bar, before providing any sensitive information such as personal particulars or account login details."

Top Headlines

Vivo X Fold 6, Vivo V80, Vivo S2 FE Now Official: Prices, Specs, Cameras, Battery, And Should You Buy
Vivo X Fold 6, Vivo V80, Vivo S2 FE Now Official: Prices, Specs, Cameras, Battery, And Should You Buy
WhatsApp May Block Users On Older iPhones, Android Phones Under New Security Measure
WhatsApp May Block Users On Older iPhones, Android Phones Under New Security Measure
Avoid These Mistakes While Buying A Laptop During Amazon Great Indian Festival 2026
Avoid These Mistakes While Buying A Laptop During Amazon Sale 2026
Thinking Of Buying An HP Laptop? How To Read (& Make The Most Of) Amazon's Festive Sale Prices
Thinking Of Buying An HP Laptop? How To Read Amazon's Festive Sale Prices

Videos

Delhi Protest: Rahul-Priyanka Remain Inside Akashvani Bhavan, Election Commission Move Still Unclear
Delhi Protest: Rahul-Priyanka Refuse To Leave Akashvani Bhavan, Demand Access To Election Commission
Delhi Protest: Rahul-Priyanka Detained After Barricade Face-Off, Opposition Leaders Taken Away
Delhi Protest: Rahul-Priyanka Detained As Opposition Clash With Police Over SIR Intensifies
CAPTAIN SMIT NEWS: फ्लाईदुबई जैसा हमला फिर होगा? अल-कायदा ने दी खुली धमकी |ABPLIVE

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget