Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat
Cybersecurity experts have revealed information on a new campaign called PHALT#BLYX that targets the European hospitality industry by using ClickFix-style lures to display patches for fictitious blue screen of death (BSoD) faults.
According to cybersecurity firm Securonix, the multi-stage campaign's ultimate objective is to distribute the DCRat remote access trojan. In late December 2025, the activity was discovered.
According to researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee, the threat actors use a phony Booking.com reservation cancelation trap to fool victims into running malicious PowerShell commands that quietly fetch and execute remote code.
The attack chain begins with a phishing email that poses as Booking.com and includes a link to a phony website (such ...

