Phishing attacks targetting CrowdStrike users after global outage: CERT-In

A Microsoft Windows outage caused by a faulty CrowdStrike Falcon Sensor update led to system crashes globally. Now a phishing campaign is targeting CrowdStrike users who were impacted by the outage

global microsoft outage, flights delay india, screen blue of death
Passengers at Terminal 3 of Delhi’s Indira Gandhi International Airport look at a blue screen displaying an error message when a technology outage affected computers worldwide. (Photo: PTI)
Rimjhim Singh New Delhi
2 min read Last Updated : Jul 30 2024 | 10:57 AM IST
The Indian Computer Emergency Response Team (CERT-In) has released an advisory alerting users to phishing attacks aimed at those affected by the recent Microsoft Windows outage. CERT-In operates under the Ministry of Electronics and Information Technology and serves as the national cybersecurity agency.
 
A global outage of Microsoft Windows occurred due to a defective update to the CrowdStrike Falcon Sensor software. This outage led to system crashes, affecting flights, businesses, banking and hospital systems worldwide.

CERT-In advisory


In its advisory, CERT-In reports an ongoing phishing campaign targeting CrowdStrike users, exploiting the global tech outage to carry out malicious activities. These activities include sending phishing emails allegedly posing as CrowdStrike support, impersonating CrowdStrike staff in phone calls, and selling software scripts claimed to automate recovery from the content update issue.
 
The advisory also warns that scammers are distributing trojan malware disguised as recovery tools. These attack campaigns can deceive unsuspecting users into installing malware, potentially leading to sensitive data leaks, system crashes, and data loss.
The advisory further recommended that users and organisations configure their firewall rules to block connections to 31 specific types of URLs, such as crowdstrikeoutage[.]info and www.crowdstrike0day[.]com, among others, as well as several hashes.

Additionally, the advisory urged the adoption of several well-known cyber hygiene practices:
- Obtain software patch updates exclusively from authentic websites and sources
- Avoid clicking on documents containing links to ‘.exe’ files, as these are typically malicious files disguised as legitimate documents
- Be wary of suspicious phone numbers, as scammers often use email-to-text services to conceal their actual phone numbers

It also advised users to only click on URLs with clear website domains and use safe browsing and filtering tools, in addition to appropriate firewalls.

The advisory said, “Look out for valid encryption certificates by checking for the green lock in the browser’s address bar, before providing sensitive information such as personal particulars or account login details.”

[With agency inputs]
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :MicrosoftCyber fraudFinancial phishingBS Web ReportsCyber crimes

First Published: Jul 30 2024 | 10:56 AM IST

Next Story