logo

ClickFix attack uses fake Windows BSOD screens to push malware

ID: afd3cdea-296d-52cb-a833-be52fba4e4f9

STIX ID: report--afd3cdea-296d-52cb-a833-be52fba4e4f9

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-01-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A phishing campaign targeting the hospitality sector in Europe impersonates Booking.com to lure victims to a cloned site that displays a fake Windows BSOD; victims are instructed to paste and execute a PowerShell command which compiles a malicious .NET project with MSBuild, deploys DCRAT (staxs.exe) via process hollowing, establishes persistence, disables Defender protections, and downloads further payloads (e.g., crypto miner) via BITS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.