logo

The ClickFix Trap: PHALT#BLYX Targets Hotels with Fake Blue Screens and DCRat

ID: c6cd02d6-7aa9-5ce3-abc8-101da95e8ec6

STIX ID: report--c6cd02d6-7aa9-5ce3-abc8-101da95e8ec6

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Ddos

...
...

A Securonix analysis describes a sophisticated cyber-espionage campaign named PHALT#BLYX targeting hospitality staff via tailored phishing that delivers a fake CAPTCHA and Blue Screen of Death to coerce victims into pasting PowerShell ‘fix’ commands. The chain leverages living‑off‑the‑land techniques (MSBuild.exe proxies, PowerShell), process injection (aspnet_compiler.exe), and deploys remote access trojans (DCRat and AsyncRAT), with Russian-language artifacts used as attribution clues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.