Threat Advisory

Daolpu Malware Exploits CrowdStrike Falcon Update Outages Through Fake Recovery Manual

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

New malware threat called Daolpu, which is being distributed via a fake recovery manual purportedly designed to fix Windows devices impacted by a recent CrowdStrike Falcon update malfunction. This fraudulent recovery tool, promoted through phishing emails, capitalizes on the confusion caused by the faulty Falcon update that led to widespread IT disruptions. The phishing campaign distributes a malicious document, masquerading as a Microsoft support bulletin, which tricks users into enabling macros. These macros then download and execute the Daolpu information-stealing malware, compromising system security by harvesting sensitive data such as account credentials, browser history, and authentication cookies from popular web browsers.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

New malware threat called Daolpu, which is being distributed via a fake recovery manual purportedly designed to fix Windows devices impacted by a recent CrowdStrike Falcon update malfunction. This fraudulent recovery tool, promoted through phishing emails, capitalizes on the confusion caused by the faulty Falcon update that led to widespread IT disruptions. The phishing campaign distributes a malicious document, masquerading as a Microsoft support bulletin, which tricks users into enabling macros. These macros then download and execute the Daolpu information-stealing malware, compromising system security by harvesting sensitive data such as account credentials, browser history, and authentication cookies from popular web browsers.[emaillocker id="1283"]

 

The malicious document, named 'New_Recovery_Tool_to_help_with_CrowdStrike_issue_impacting_ Windows.docm', contains embedded macros that activate upon enabling. These macros download a base64-encoded DLL file from an external server and decode it using Windows certutil. The decoded file, a DLL, is then executed to deploy the Daolpu stealer. Once active, Daolpu terminates Chrome processes to access and exfiltrate login data and cookies stored in Chrome, Edge, Firefox, and Cốc Cốc browsers. The stolen data is temporarily saved to a file named 'result.txt' in the %TMP% directory before being sent to a command-and-control server. The presence of this result.txt file can serve as an indicator of compromise for potentially affected systems.

 

The Daolpu malware incident underscores the persistent and adaptive nature of cyber threats, especially during periods of system vulnerability and IT disruptions. CrowdStrike has emphasized the importance of only following advice from trusted sources and verifying communications authenticity to mitigate such threats. Users are advised to implement stringent security measures, such as training to avoid untrusted files, using browser download protections, and monitoring for specific indicators of compromise like the result.txt file in the %TMP% directory. The fallout from the CrowdStrike Falcon update mishap is expected to continue, with cybercriminals likely to exploit the situation further, necessitating heightened vigilance and robust security protocols.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1204 User Execution
Credential Access T1555 Credentials from Password Stores
Command and Control T1071 Application Layer Protocol
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/fake-crowdstrike-repair-manual-pushes-new-daolpu-infostealer-malware/

[/emaillocker]
crossmenu