logo

Hospitality Sector Hit By PHALT#BLYX ClickFix Malware Campaign

ID: 15406046-c1d5-50c7-86c9-113fb72031d0

STIX ID: report--15406046-c1d5-50c7-86c9-113fb72031d0

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

...
...

Securonix observed a multi-stage phishing campaign (PHALT#BLYX) targeting hospitality organizations during the holiday season: Booking.com-themed emails redirect victims to cloned sites that prompt users to paste a PowerShell command, which downloads a project file executed by MSBuild.exe (living-off-the-land) and installs an obfuscated DCRat remote-access trojan capable of keylogging, process injection, persistence via Internet Shortcut files, and altering Defender exclusions; researchers attribute the activity to Russian-speaking actors and recommend user training, monitoring of trusted binaries (like MSBuild.exe), and behavioral/process-level detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.