Cybersecurity experts have revealed information on a new campaign called PHALT#BLYX that targets the European hospitality industry by using ClickFix-style lures to display patches for fictitious blue screen of death (BSoD) faults.
According to cybersecurity firm Securonix, the multi-stage campaign’s ultimate objective is to distribute the DCRat remote access trojan. In late December 2025, the activity was discovered.
According to researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee, the threat actors use a phony Booking.com reservation cancelation trap to fool victims into running malicious PowerShell commands that quietly fetch and execute remote code.
The attack chain begins with a phishing email that poses as Booking.com and includes a link to a phony website (such as “low-house[.]com”). The communications alert recipients read more about Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
