logo

Fake Booking.com lures and BSoD scams spread DCRat in European hospitality sector

ID: 12f68d80-c5ff-57ef-8ce0-80ef504cc263

STIX ID: report--12f68d80-c5ff-57ef-8ce0-80ef504cc263

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

PHALT#BLYX is a late-December 2025 campaign targeting European hospitality organizations with Booking.com-themed phishing that routes victims through fake CAPTCHA/BSoD pages to execute malicious PowerShell and an MSBuild project (v.proj). The multi-stage chain deploys a packed .NET loader (staxs.exe) that decrypts configuration with AES-256/PBKDF2, installs DCRat (enabling remote access, keylogging, process hollowing, persistence via a Startup .url), and connects to C2 domains; Russian-language artifacts suggest Russian-speaking operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.