logo

RST TI Report Digest: 12 Jan 2026

ID: 805008fa-d424-5abf-9f51-fd2450c53ef8

STIX ID: report--805008fa-d424-5abf-9f51-fd2450c53ef8

Feed Name: RST Cloud Blog

Threat Score
72/100

Date Published: 2026-01-12

Date Updated: 2026-04-29

Author: RST Cloud

...
...

**PHALT#BLYX** is a targeted malware campaign against the hospitality sector that delivers a loader (staxs.exe) via phishing and counterfeit Booking.com pages; the loader injects into legitimate processes, employs evasion (Defender exclusions, privilege checks), ensures persistence using Internet Shortcut files, and distributes multiple infostealers and RATs (e.g., RedLine, Vidar, DCRat/AsyncRAT). The report includes detailed TTPs (clipboard injection, LOLBIN use, process hollowing/injection, dead drop techniques) and a set of IoCs (IPs, domains, URLs, and numerous SHA-256 hashes) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.