Russian hackers target European hospitality industry with ‘blue screen of death’ malware
ID: 494c3c5d-1e38-5fcc-aa62-76e5d27a00e1
STIX ID: report--494c3c5d-1e38-5fcc-aa62-76e5d27a00e1
Feed Name: The Record from Recorded Future News
Researchers from Securonix observed a phishing campaign called PHALT#BLYX targeting European hotels and hospitality organizations by sending fake reservation cancellation emails that lead victims to a fake booking page and a staged Blue Screen of Death; victims are coerced to paste a malicious command that installs DCRat, disables Windows Defender, and steals credentials and clipboard data. The campaign leverages the “ClickFix” social-engineering technique and abuses trusted binaries like MSBuild.exe for stealth and persistence, and telemetry/strings suggest ties to Russian-speaking criminal actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
