More

    Securonix warns of malware campaign targeting hospitality sector

    A new report out today from cybersecurity company Securonix Inc. is warning of an ongoing malware campaign targeting the hospitality sector, using psychological manipulation and trusted Windows tools to evade detection and establish long-term system access.

    The “PHALT#BLYX” campaign combines phishing, fake system errors and living-off-the-land techniques to deliver a customized version of the DCRat remote access trojan.

    The attackers rely on high-pressure social engineering techniques rather than using traditional malware downloads to trick victims into manually executing the malicious code themselves.

    A PHALT#BLYX attack typically begins with phishing emails impersonating Booking.com reservation cancellation notices. The messages often include large charges to create urgency and are aimed at hospitality organizations during peak travel periods. When a victim clicks on a link, they are taken to a high-fidelity fake Booking.com website hosted on attacker-controlled infrastructure.

    Upon arrival at the fake site, victims are presented with a fake browser error followed by a simulated Blue Screen of Death and are then instructed to “fix” the issue by pasting preloaded content from their clipboard into the Windows Run dialog. The “ClickFix” technique bypasses many automated security controls by relying on user interaction rather than automated script execution.

    Once executed, the pasted command launches a multistage infection chain using PowerShell and Microsoft’s legitimate MSBuild.exe utility. MSBuild is used to compile and execute a malicious project file to allow the payload to run under the cover of a trusted Windows binary.

    The malware then disables Windows Defender protections, establishes persistence and downloads the final DCRat payload. The deployed DCRat variant supports full remote control of infected systems, including keylogging, command execution and the ability to drop additional malware. Securonix’s researchers also identified a process hollowing technique that injects malicious code into legitimate Windows processes to conceal activity.

    Though the exact threat actor behind the malware has yet to be identified, artifacts within the malware, including Cyrillic debug strings and infrastructure overlaps, point toward a likely connection to Russian-speaking threat actors.

    So far, the campaign has only been focused on hospitality organizations in Europe, but Securonix is warning that the underlying tactics could easily be adapted to other industries.

    “While the campaign targets the hospitality sector with specific financial lures, the underlying tradecraft suggests a threat actor capable of adapting to various industries,” the researchers conclude. “As these tactics continue to evolve, organizations must look beyond file-based detection and focus on behavioral anomalies and process lineage to identify and stop these multistaged attacks.”

    Image: SiliconANGLE/Ideogram

    Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

    • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
    • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

    About SiliconANGLE Media

    SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

    Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

     

    Latest articles

    Related articles