Skip to content

UPDATED 09:00 EST / JANUARY 05 2026

SECURITY

Securonix warns of malware campaign targeting hospitality sector

A new report out today from cybersecurity company Securonix Inc. is warning of an ongoing malware campaign targeting the hospitality sector, using psychological manipulation and trusted Windows tools to evade detection and establish long-term system access.

The “PHALT#BLYX” campaign combines phishing, fake system errors and living-off-the-land techniques to deliver a customized version of the DCRat remote access trojan.

The attackers rely on high-pressure social engineering techniques rather than using traditional malware downloads to trick victims into manually executing the malicious code themselves.

A PHALT#BLYX attack typically begins with phishing emails impersonating Booking.com reservation cancellation notices. The messages often include large charges to create urgency and are aimed at hospitality organizations during peak travel periods. When a victim clicks on a link, they are taken to a high-fidelity fake Booking.com website hosted on attacker-controlled infrastructure.

Upon arrival at the fake site, victims are presented with a fake browser error followed by a simulated Blue Screen of Death and are then instructed to “fix” the issue by pasting preloaded content from their clipboard into the Windows Run dialog. The “ClickFix” technique bypasses many automated security controls by relying on user interaction rather than automated script execution.

Once executed, the pasted command launches a multistage infection chain using PowerShell and Microsoft’s legitimate MSBuild.exe utility. MSBuild is used to compile and execute a malicious project file to allow the payload to run under the cover of a trusted Windows binary.

The malware then disables Windows Defender protections, establishes persistence and downloads the final DCRat payload. The deployed DCRat variant supports full remote control of infected systems, including keylogging, command execution and the ability to drop additional malware. Securonix’s researchers also identified a process hollowing technique that injects malicious code into legitimate Windows processes to conceal activity.

Though the exact threat actor behind the malware has yet to be identified, artifacts within the malware, including Cyrillic debug strings and infrastructure overlaps, point toward a likely connection to Russian-speaking threat actors.

So far, the campaign has only been focused on hospitality organizations in Europe, but Securonix is warning that the underlying tactics could easily be adapted to other industries.

“While the campaign targets the hospitality sector with specific financial lures, the underlying tradecraft suggests a threat actor capable of adapting to various industries,” the researchers conclude. “As these tactics continue to evolve, organizations must look beyond file-based detection and focus on behavioral anomalies and process lineage to identify and stop these multistaged attacks.”

Image: SiliconANGLE/Ideogram

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.

Sign in or create an account

SIGN IN

OR

New User? SIGN UP

Join us

SIGN UP

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry