logo

Russian hackers target European hospitality industry with ‘blue screen of death’ malware

ID: 494c3c5d-1e38-5fcc-aa62-76e5d27a00e1

STIX ID: report--494c3c5d-1e38-5fcc-aa62-76e5d27a00e1

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2026-01-05

Date Updated: 2026-05-01

...
...

Researchers from Securonix observed a phishing campaign called PHALT#BLYX targeting European hotels and hospitality organizations by sending fake reservation cancellation emails that lead victims to a fake booking page and a staged Blue Screen of Death; victims are coerced to paste a malicious command that installs DCRat, disables Windows Defender, and steals credentials and clipboard data. The campaign leverages the “ClickFix” social-engineering technique and abuses trusted binaries like MSBuild.exe for stealth and persistence, and telemetry/strings suggest ties to Russian-speaking criminal actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.