New ClickFix Attack Uses Fake BSOD to Trick Users into Running Malicious Code
ID: b8acd82e-63c4-5a6d-a593-898024792297
STIX ID: report--b8acd82e-63c4-5a6d-a593-898024792297
Feed Name: GBHackers
Securonix researchers detail PHALT#BLYX, a targeted campaign against European hospitality organizations that lures victims with fake Booking.com cancellation emails; victims are tricked into pasting a PowerShell script that downloads an MSBuild project which executes a heavily obfuscated DCRat payload. The chain uses a faux BSOD to coerce clipboard actions, abuses MSBuild.exe to bypass allowlisting, disables Defender via exclusions, establishes persistence with a Startup .url file, and injects the RAT into aspnet_compiler.exe; Cyrillic debug strings and DCRat indicators suggest Russian-linked actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
