TI Mindmap HUB
Threat Intelligence Report

Analyzing PHALT#BLYX: How Fake BSODs and Trusted Build Tools Are Used to Construct a Malware Infection

📅 January 24, 2026 📰 www.securonix.com 🔍 0 CVE(s) referenced

A highly targeted phishing campaign exploits fake Booking.com cancellations and psychological “ClickFix” tactics to trick hospitality sector victims into manually executing a multi-stage, Russian-linked DCRat malware, leveraging trusted tools like MSBuild.exe to stealthily bypass defenses, disable antivirus, and maintain persistent, full remote access.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle