← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Malware Distributed Using Falcon Sensor Update Phishing Lure
CrowdStrike Intelligence uncovered a phishing campaign impersonating CrowdStrike and distributing malicious files containing a Microsoft Installer (MSI) loader. The loader executes the commodity stealer 'Lumma Stealer' packed with 'CypherIt'. This campaign is likely linked to a previous 'Lumma Stealer' distribution effort leveraging advanced social engineering techniques. The malware evades detection by terminating if security products are detected, and employs multiple layers of obfuscation. It ultimately connects to command and control servers to exfiltrate stolen data.
MITRE ATT&CK & Malware Families
Indicators of Compromise (2 / 36 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 6ee7ddebff0a2b78c7ac30f6e00d1d11 | — | 2024-07-29 | |
| FileHash-MD5 | 8a9baf0bf2ffabd39007a630a430a29b | — | 2024-07-29 |