Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Likely eCrime Actor Uses Filenames Capitalizing on July 19, 2024, Falcon Sensor Content Issues in Operation Targeting LATAM-Based CrowdStrike Customers
Crowdstrike ^ | 20 Jul 2024 | Counter Adversary Operations

Posted on 07/20/2024 7:33:15 AM PDT by blueplum

CrowdStrike Intelligence has since observed threat actors leveraging the event to distribute a malicious ZIP archive named crowdstrike-hotfix.zip. The ZIP archive contains a HijackLoader payload...Notably, Spanish filenames and instructions within the ZIP archive indicate this campaign is likely targeting Latin America-based (LATAM) CrowdStrike customers.

(Excerpt) Read more at crowdstrike.com ...


TOPICS: Business/Economy; News/Current Events
KEYWORDS: crowdstrike; cybercrime; falcon; it; latinamerica; microsoft
Click The Pic
Hey! FReepers!
Help Fill The Tank!
How About It? Huh?
It Ain't Askin' Too Much
Ya Know....

Click here: to donate by Credit Card

Or here: to donate by PayPal

Or by mail to: Free Republic, LLC - PO Box 9771 - Fresno, CA 93794

Thank you very much and God bless you.

see article for Details, specific file names, and Indicators of Compromise
1 posted on 07/20/2024 7:33:15 AM PDT by blueplum
[ Post Reply | Private Reply | View Replies]

To: blueplum

huh?


2 posted on 07/20/2024 7:42:32 AM PDT by JonPreston ( ✌ ☮️ )
[ Post Reply | Private Reply | To 1 | View Replies]

To: blueplum

> crowdstrike-hotfix.zip

Any sysadmin that opens an email with a file named “crowdstrike-hotfix.zip” deserves what happens to them. ;-)


3 posted on 07/20/2024 7:44:51 AM PDT by glorgau
[ Post Reply | Private Reply | To 1 | View Replies]

To: glorgau

>> Any sysadmin that opens an email with a file named “crowdstrike-hotfix.zip” deserves what happens to them. ;-)

Yeah, but the company they serve may not deserve it.

In other news, I wonder how long before CrowdStrike is bankrupt. They RICHLY deserve THAT.


4 posted on 07/20/2024 8:03:04 AM PDT by Nervous Tick ("First the Saturday people, then the Sunday people...": ISLAM is the problem!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: blueplum

I wonder why they assume the Spanish indicates the target, and not the source.

Are the instructions ONLY in Spanish?

Most programmers want to comment and debug in a language they can read. A programming language may force English (for now), but the rest doesn’t.


5 posted on 07/20/2024 8:04:22 AM PDT by Empire_of_Liberty ( )
[ Post Reply | Private Reply | To 1 | View Replies]

To: blueplum

Somewhat curious whether Crowd-strike was shorted and someone made a load of coin off this “cyber attack”.


6 posted on 07/20/2024 8:10:37 AM PDT by LastDayz (A Blunt and Brazen Texan. I Will Not Be Assimilated.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: glorgau

Yeah but the sysadmin job was outsourced so they weren’t making that much money and they just moved on.


7 posted on 07/20/2024 8:24:35 AM PDT by BipolarBob (First I was called a big fat lair and then showed a certain Lake of Respect.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: blueplum

I’m not techie, just a very old guy enjoying the ride. However, when I read the word “Crowdsource’ I immediately thought back to 2016 when Hilary claimed her computers had been hacked by Russian operatives. She should have turned them over to the FBI for investigation but she didn’t. She called in a private company called “CrowdSource.” It then supposedly confirmed the claim it was a Russian effort to interfere with the election. That claim later was found to be false. Or was a different company??


8 posted on 07/20/2024 8:32:58 AM PDT by elpadre ( )
[ Post Reply | Private Reply | To 1 | View Replies]

To: blueplum

engish please


9 posted on 07/20/2024 8:33:30 AM PDT by coalminersson
[ Post Reply | Private Reply | To 1 | View Replies]

To: elpadre

No, the same company, your memory serves you well.


10 posted on 07/20/2024 8:34:15 AM PDT by OldHarbor (strained statutory arguments, appeals to inconsistent history, reliance on out-of-circuit authority)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Nervous Tick
Yeah, but the company they serve may not deserve it.

The case could be made, at least some of the time, that they should have hired a sysadmin that knows what he is doing. Maybe IT is the wrong place for DEI.

11 posted on 07/20/2024 9:01:32 AM PDT by ChildOfThe60s ("If you can remember the 60s....you weren't really there")
[ Post Reply | Private Reply | To 4 | View Replies]

To: ChildOfThe60s

>> The case could be made, at least some of the time, that they should have hired a sysadmin that knows what he is doing. Maybe IT is the wrong place for DEI.

You are spot on in that observation. I initially wrote “company they serve does not deserve it”, but changed it to “may not deserve” because I recognized the truth as you stated it.


12 posted on 07/20/2024 9:12:14 AM PDT by Nervous Tick ("First the Saturday people, then the Sunday people...": ISLAM is the problem!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: LastDayz
most of this is Greek to me but for what it's worth:
tech stocks lost $900 billion overall Wednesday "biggest drop since 2022'. Crowdstrike may have been part of that sell-off, with a further drop on Friday, if the numbers below make sense to someone more knowledgeable than I am. .
following the outage, according to Marketwatch Crowdstrike " declined 11.1% Friday to log its worst one-day drop since it fell 14.8% on Nov. 30, 2022. It had been down as much as 15.4% earlier in the session....CrowdStrike CEO George Kurtz is taking a $42 million personal hit from stock’s drop..CrowdStrike shares have lost 19.2% over their current four-session streak of losses, and are down 19.4% this year so far. The stock fell 3.4% in Thursday’s action after a downgrade to sell... "
13 posted on 07/20/2024 9:17:27 AM PDT by blueplum ("...this moment is your moment: it belongs to you... " President Donald J. Trump, Jan 20, 2017) )
[ Post Reply | Private Reply | To 6 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson