logo

Fake Windows BSODs check in at Europe's hotels to con staff into running malware

ID: 2919ac84-682d-547a-8823-416768ead88b

STIX ID: report--2919ac84-682d-547a-8823-416768ead88b

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-01-06

Date Updated: 2026-04-26

Author: Carly Page

...
...

Securonix researchers detail PHALT#BLYX, a campaign targeting European hospitality staff via Booking.com-themed phishing that displays a fake Windows BSOD to coerce victims into running a malicious PowerShell command; the attackers pivoted to MSBuild-based execution to drop a DCRat remote-access trojan, with artifacts and euro-focused targeting suggesting Russia-linked actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.