ClickFix Campaign Serves Up Fake Blue Screen of Death
ID: 7a3bfd4c-cad7-5585-b41c-cf277b13900b
STIX ID: report--7a3bfd4c-cad7-5585-b41c-cf277b13900b
Feed Name: Dark Reading
Date Published: 2026-01-06
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
PHALT#BLYX is a ClickFix-based campaign targeting the hospitality sector that lures victims with fake Booking.com reservation cancellation pages and fake captcha/BSOD prompts to execute PowerShell commands. The attackers use MSBuild.exe to compile a project file that deploys a heavily obfuscated DCRat (Dark Crystal RAT) capable of process hollowing, keylogging, persistence, and dropping secondary payloads; indicators include abuse of MSBuild, aspnet_compiler.exe and tampering of Windows Defender exclusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
