pro-Iranian hacktivist group Handala have stated on Twitter that they impersonated CrowdStrike in emails to Israeli companies to distribute the data wiper - emails include a PDF that contains further instructions on running the fake update, as well as a link to download a malicious ZIP archive from a file hosting service. This zip file contains an executable named 'Crowdstrike.exe.'
NCSC also warned that it observed an increase in phishing msgs
@ecksmc Color me unsurprised.