The ClickFix Trap: PHALT#BLYX Targets Hotels with Fake Blue Screens and DCRat
ID: c6cd02d6-7aa9-5ce3-abc8-101da95e8ec6
STIX ID: report--c6cd02d6-7aa9-5ce3-abc8-101da95e8ec6
Feed Name: securityonline.info
A Securonix analysis describes a sophisticated cyber-espionage campaign named PHALT#BLYX targeting hospitality staff via tailored phishing that delivers a fake CAPTCHA and Blue Screen of Death to coerce victims into pasting PowerShell ‘fix’ commands. The chain leverages living‑off‑the‑land techniques (MSBuild.exe proxies, PowerShell), process injection (aspnet_compiler.exe), and deploys remote access trojans (DCRat and AsyncRAT), with Russian-language artifacts used as attribution clues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
