Cybersecurity researchers at Securonix have identified a new malicious campaign, dubbed PHALT#BLYX, that uses a fake "Blue Screen of Death" (BSOD) to trick users into installing malware.
How the Attack Works
- Phishing Email: The attack starts with a fake email disguised as a Booking.com notification regarding a reservation cancellation and a high pending charge.
- The Fake BSOD: Clicking the link in the email leads to a website that mimics a Windows Blue Screen of Death.
- Social Engineering: The site provides instructions to "fix" the error. It directs the user to open the Windows "Run" box and paste a specific malicious code.
- Infection: Once the code is executed, it downloads DCRat, a remote access trojan.
The Danger of DCRat
Once installed, DCRat gives attackers full remote control over the infected computer. This allows them to:
- Record keystrokes (keylogging).
- Steal sensitive personal and financial information.
- Monitor user activity in real-time.
To stay safe, never run commands or codes provided by unsolicited websites, and always verify reservation details directly through official apps or websites.


