logo

ClickFix Campaign Serves Up Fake Blue Screen of Death

ID: 7a3bfd4c-cad7-5585-b41c-cf277b13900b

STIX ID: report--7a3bfd4c-cad7-5585-b41c-cf277b13900b

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

PHALT#BLYX is a ClickFix-based campaign targeting the hospitality sector that lures victims with fake Booking.com reservation cancellation pages and fake captcha/BSOD prompts to execute PowerShell commands. The attackers use MSBuild.exe to compile a project file that deploys a heavily obfuscated DCRat (Dark Crystal RAT) capable of process hollowing, keylogging, persistence, and dropping secondary payloads; indicators include abuse of MSBuild, aspnet_compiler.exe and tampering of Windows Defender exclusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.