{"id":342,"date":"2024-07-20T14:17:39","date_gmt":"2024-07-20T14:17:39","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=342"},"modified":"2024-07-22T14:18:58","modified_gmt":"2024-07-22T14:18:58","slug":"cybercriminals-exploit-crowdstrike-update-mishap-to-distribute-remcos-rat-malware","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2024\/07\/20\/cybercriminals-exploit-crowdstrike-update-mishap-to-distribute-remcos-rat-malware\/","title":{"rendered":"Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Cybersecurity firm CrowdStrike, which is facing the heat for causing&nbsp;<a href=\"https:\/\/thehackernews.com\/2024\/07\/faulty-crowdstrike-update-crashes.html\">worldwide IT disruptions<\/a>&nbsp;by pushing out a flawed update to Windows devices, is now warning that threat actors are exploiting the situation to distribute Remcos RAT to its customers in Latin America under the guise of providing a hotfix.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attack chains involve distributing a ZIP archive file named &#8220;<a href=\"https:\/\/www.virustotal.com\/gui\/file\/c44506fe6e1ede5a104008755abf5b6ace51f1a84ad656a2dccc7f2c39c0eca2\">crowdstrike-hotfix.zip<\/a>,&#8221; which contains a malware loader named&nbsp;<a href=\"https:\/\/thehackernews.com\/2024\/06\/cybercriminals-exploit-free-software.html\">Hijack Loader<\/a>&nbsp;(aka DOILoader or IDAT Loader) that, in turn, launches the Remcos RAT payload.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2024\/07\/20\/cybercriminals-exploit-crowdstrike-update-mishap-to-distribute-remcos-rat-malware\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2024\/07\/cybercriminals-exploit-crowdstrike.html\">Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware (thehackernews.com)<\/a><span class=\"screen-reader-text\">: Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Cybersecurity firm CrowdStrike, which is facing the heat for causing&nbsp;worldwide IT disruptions&nbsp;by pushing out a flawed update to Windows devices, is now warning that threat actors are exploiting the situation to distribute Remcos RAT to its customers in Latin America under the guise of providing a hotfix. The attack chains&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20,4],"tags":[31],"class_list":["post-342","post","type-post","status-publish","format-standard","hentry","category-cybersecurity","category-ransomware","tag-31"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=342"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/342\/revisions"}],"predecessor-version":[{"id":343,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/342\/revisions\/343"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}