Watch out! This fake Windows BSOD is a trap
ID: 7318038b-4982-5848-a422-cb560f8afbab
STIX ID: report--7318038b-4982-5848-a422-cb560f8afbab
Feed Name: ZDNet Security
ZDNET summarizes Securonix’s analysis of PHALT#BLYX, a targeted campaign against the hospitality sector that lures victims via Booking.com-themed phishing and fake CAPTCHA/BSOD pages. Victims are social-engineered to paste a malicious command (ClickFix), which runs a PowerShell script that uses MSBuild to fetch an obfuscated DCRat remote access trojan, disables Defender, establishes persistence, and can deliver secondary payloads; the report includes detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
