BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

PHALT#BLYX: Booking Phish Fakes BSoD, Installs DCRat -Hotels

PHALT#BLYX phishing campaign uses fake Booking.com BSoD pages and MSBuild-based loaders to disable Defender and deploy DCRat against European hospitality organizations.

  • A campaign called PHALT#BLYX used fake ClickFix-style pages to show bogus blue screen of death errors and trick victims into running commands.
  • Phishing emails impersonated Booking.com and redirected targets to a site that prompted a Run-dialog PowerShell command, which fetched a multi-stage loader.
  • The loader used a custom MSBuild project to run payloads via MSBuild.exe, disable or evade Microsoft Defender Antivirus, and install the DCRat remote access trojan.
  • Indicators include domains like 2fa-bns[.]com and room charges in Euros, suggesting a focus on European hospitality organizations and links to Russian-language components.

Researchers at Securonix disclosed a late-December 2025 campaign named PHALT#BLYX that targeted European hospitality organizations to deliver the remote access trojan DCRat. The attack used fake ClickFix-style pages showing a bogus blue screen of death to trick victims into running commands.

- Advertisement -

“For initial access, the threat actors utilize a fake Booking.com reservation cancellation lure to trick victims into executing malicious PowerShell commands, which silently fetch and execute remote code,” researchers noted in their report linked to Securonix (Malware-infection/”>read more).

The attack begins with a phishing email impersonating Booking.com, warning of a reservation cancellation and linking to a fake site. The site serves a CAPTCHA and then a fake BSoD page with “recovery instructions” that ask users to open the Run dialog and paste a command. That command runs a PowerShell dropper.

The PowerShell dropper downloads a custom MSBuild project file named “v.proj” from 2fa-bns[.]com and executes it with MSBuild.exe. The embedded payload adjusts Microsoft Defender Antivirus exclusions, establishes persistence in the Startup folder, and downloads and launches DCRat.

If run with administrator privileges, the malware can disable Defender; otherwise it triggers a User Account Control prompt repeatedly to try to gain elevation. The code also opens the real Booking.com admin page as a distraction.

- Advertisement -

DCRat is a .NET RAT that can profile systems, log keystrokes, execute commands, and load plugins such as cryptocurrency miners. “The phishing emails notably feature room charge details in Euros, suggesting the campaign is actively targeting European organizations,” and “The use of a customized MSBuild project file to proxy execution, coupled with aggressive tampering of Windows Defender exclusions, demonstrates a deep understanding of modern endpoint protection mechanisms,” Securonix added.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Nears $64K Despite Iran Tensions, Trader Caution

Bitcoin regained the $64,000 level despite renewed geopolitical tensions involving the US, Iran, and...

Micron’s AI HBM Boom: $435 to $1,750 Price Target Split

Wall Street's 2026 price targets for Micron stock show extreme divergence, ranging from around...

AI Chatbots May Reinforce Delusions in Vulnerable Users

Researchers propose a new "amplification spiral" framework to explain how AI chatbots could reinforce...

Bitcoin Plunges 50%, Sparking Fears of Imminent Market Collapse

Bitcoin's price has fallen to half its October 2025 peak, sparking fears of a...

Dash Eyes Philippines for Crypto Payments Expansion

Dash is exploring the Philippines as a target market for its low-cost crypto payment...

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading