Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New ClickFix Attack Uses Fake BSOD to Trick Users into Running Malicious Code

Securonix threat researchers have identified a sophisticated malware campaign, named PHALT#BLYX, targeting the hospitality sector. This campaign utilizes a social engineering tactic known as "ClickFix".

Securonix threat researchers have identified a sophisticated malware campaign, named PHALT#BLYX, targeting the hospitality sector. This campaign utilizes a social engineering tactic known as "ClickFix".

The campaign specifically targets European organizations during the holiday season by leveraging fake Booking.com reservation cancellations to deploy a Russian-linked DCRat payload.

The infection chain starts with a phishing email, impersonating Booking.com, notifying recipients of a reservation cancellation with a significant financial charge. Upon clicking the "See Details" link, users are redirected to a fraudulent page mimicking the Booking.com interface. The page displays a fake "Loading is taking too long" error. Clicking "Refresh" triggers a simulated full-screen BSOD crash. An overlay instructs users to perform a "fix" by pressing specific key combinations, leading to the execution of a malicious PowerShell script.

This sequence bypasses automated email security filters by infecting the system via the Windows Run dialog.

Securonix threat researchers have identified a sophisticated malware campaign, named PHALT#BLYX, targeting the hospitality sector.
Leo Underwood · Thehackingpost

The attack chain is notable for its use of the "Blue Screen of Death" deception and the exploitation of the legitimate Windows tool MSBuild.exe to bypass security defenses.

Once the PowerShell script is executed, it downloads a project file which is compiled and executed using MSBuild.exe, allowing the malware to bypass application allowlisting and antivirus detection.

The malware adds exclusions to Windows Defender for the ProgramData directory. It establishes persistence by creating an Internet Shortcut file in the Startup folder, disguised as a cleanup script.

Advertisement

The final payload is a heavily obfuscated version of DCRat, capable of process hollowing, keylogging, and deploying secondary payloads. This RAT is injected into the legitimate aspnet_compiler.exe process to conceal its activity.

Cyrillic debug strings found within the project file, alongside the use of DCRat, suggest a link to Russian threat actors. These elements indicate the campaign's origin.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories