EXECUTIVE SUMMARY
New malware threat called Daolpu, which is being distributed via a fake recovery manual purportedly designed to fix Windows devices impacted by a recent CrowdStrike Falcon update malfunction. This fraudulent recovery tool, promoted through phishing emails, capitalizes on the confusion caused by the faulty Falcon update that led to widespread IT disruptions. The phishing campaign distributes a malicious document, masquerading as a Microsoft support bulletin, which tricks users into enabling macros. These macros then download and execute the Daolpu information-stealing malware, compromising system security by harvesting sensitive data such as account credentials, browser history, and authentication cookies from popular web browsers.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
New malware threat called Daolpu, which is being distributed via a fake recovery manual purportedly designed to fix Windows devices impacted by a recent CrowdStrike Falcon update malfunction. This fraudulent recovery tool, promoted through phishing emails, capitalizes on the confusion caused by the faulty Falcon update that led to widespread IT disruptions. The phishing campaign distributes a malicious document, masquerading as a Microsoft support bulletin, which tricks users into enabling macros. These macros then download and execute the Daolpu information-stealing malware, compromising system security by harvesting sensitive data such as account credentials, browser history, and authentication cookies from popular web browsers.[emaillocker id="1283"]
The malicious document, named 'New_Recovery_Tool_to_help_with_CrowdStrike_issue_impacting_ Windows.docm', contains embedded macros that activate upon enabling. These macros download a base64-encoded DLL file from an external server and decode it using Windows certutil. The decoded file, a DLL, is then executed to deploy the Daolpu stealer. Once active, Daolpu terminates Chrome processes to access and exfiltrate login data and cookies stored in Chrome, Edge, Firefox, and Cốc Cốc browsers. The stolen data is temporarily saved to a file named 'result.txt' in the %TMP% directory before being sent to a command-and-control server. The presence of this result.txt file can serve as an indicator of compromise for potentially affected systems.
The Daolpu malware incident underscores the persistent and adaptive nature of cyber threats, especially during periods of system vulnerability and IT disruptions. CrowdStrike has emphasized the importance of only following advice from trusted sources and verifying communications authenticity to mitigate such threats. Users are advised to implement stringent security measures, such as training to avoid untrusted files, using browser download protections, and monitoring for specific indicators of compromise like the result.txt file in the %TMP% directory. The fallout from the CrowdStrike Falcon update mishap is expected to continue, with cybercriminals likely to exploit the situation further, necessitating heightened vigilance and robust security protocols.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1204 | User Execution |
| Credential Access | T1555 | Credentials from Password Stores |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/fake-crowdstrike-repair-manual-pushes-new-daolpu-infostealer-malware/