logo

Watch out! This fake Windows BSOD is a trap

ID: 7318038b-4982-5848-a422-cb560f8afbab

STIX ID: report--7318038b-4982-5848-a422-cb560f8afbab

Feed Name: ZDNet Security

Threat Score
70/100

Date Published: 2026-01-08

Date Updated: 2026-04-26

...
...

ZDNET summarizes Securonix’s analysis of PHALT#BLYX, a targeted campaign against the hospitality sector that lures victims via Booking.com-themed phishing and fake CAPTCHA/BSOD pages. Victims are social-engineered to paste a malicious command (ClickFix), which runs a PowerShell script that uses MSBuild to fetch an obfuscated DCRat remote access trojan, disables Defender, establishes persistence, and can deliver secondary payloads; the report includes detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.