{"id":9669,"date":"2026-01-06T10:04:41","date_gmt":"2026-01-06T10:04:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/06\/new-clickfix-attack-uses-fake-windows-bsod-screens-to-trick-users-into-executing-malicious-code\/"},"modified":"2026-01-06T10:04:41","modified_gmt":"2026-01-06T10:04:41","slug":"new-clickfix-attack-uses-fake-windows-bsod-screens-to-trick-users-into-executing-malicious-code","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/06\/new-clickfix-attack-uses-fake-windows-bsod-screens-to-trick-users-into-executing-malicious-code\/","title":{"rendered":"New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code"},"content":{"rendered":"<p>    New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated malware campaign called PHALTBLYX has emerged, combining social engineering deception with advanced evasion techniques to compromise hospitality sector organizations. <\/p>\n<p>The attack chain begins with phishing emails impersonating Booking.com, featuring urgent reservation cancellation alerts with large financial charges displayed in euros. <\/p>\n<p>These messages direct victims to <a href=\"https:\/\/cybersecuritynews.com\/beware-of-fake-booking-com-sites\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake Booking.com<\/a> websites that appear visually identical to the legitimate service, exploiting user anxiety about fraudulent transactions.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEige1nJA5vNqXDxHbQ1-5zacClTfqhyP6uZj3y6sHga4qryA00hWtpTtCqzRyId4nQHg4LCvbokuF8UXOm77In-FCscQAF6mLl0sKvATRnBK-hrTYAWRRV5NdOB8WP_1KLP5i6KewSlNXzQzk2VoKmGDjJysMey6ioG85gywhN5qObtcEExL9enNt5SUF8\/s16000\/fake%2520Booking.com%2520website%2520%28Source%2520-%2520Securonix%29.webp?ssl=1\" alt=\"Fake Booking.com website (Source - Securonix)\"><figcaption class=\"wp-element-caption\">Fake Booking.com website (Source \u2013 Securonix)<\/figcaption><\/figure>\n<\/div>\n<p>The attack progresses through a carefully orchestrated series of stages designed to bypass traditional security controls. Once victims click the refresh button on the fake page, their browser displays a full-screen blue screen of death animation. <\/p>\n<p>This simulated crash prompts users to follow on-screen instructions that involve pressing specific keyboard combinations. <\/p>\n<p>Securonix analysts <a href=\"https:\/\/www.securonix.com\/blog\/analyzing-phaltblyx-how-fake-bsods-and-trusted-build-tools-are-used-to-construct-a-malware-infection\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that the malware silently copies a PowerShell command to the clipboard, which victims unknowingly execute when following the displayed instructions.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgyvJ10CMg6a8ai8UZbor2fJ5na6HJo7mBxHCY-Kr7nKVedGW8o6KpWebkMfVsp0IUT0Fo4_pjjVfUY207p0Z7zX6YOGprJlfljdHz6sG8PQ3H5KjUNikD5AgMxULeX3IB7BjtgpftHy86JzX5c4KKFKTgVRi6ldGI14ajITRWqJxl-oL5gDQJ-3P5ApfI\/s16000\/Fake%2520crash%2520screen%2520%28Source%2520-%2520Securonix%29.webp?ssl=1\" alt=\"Fake crash screen (Source - Securonix)\"><figcaption class=\"wp-element-caption\">Fake crash screen (Source \u2013 Securonix)<\/figcaption><\/figure>\n<\/div>\n<p>Securonix researchers noted that this click-fix <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> method represents a critical evolution in the attack\u2019s delivery mechanism. <\/p>\n<p>The technique relies on manual user execution rather than automated processes, effectively circumventing security controls that would block script execution. <\/p>\n<p>The malicious PowerShell command performs several functions, including opening the legitimate Booking.com admin page as a distraction while downloading an MSBuild project file from remote servers.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism\"><strong>Infection mechanism<\/strong><\/h2>\n<p>The infection mechanism leverages Microsoft\u2019s legitimate MSBuild.exe compiler to execute the downloaded v.proj file, a technique known as living off the land. <\/p>\n<p>This approach allows malware to <a href=\"https:\/\/cybersecuritynews.com\/how-to-choose-reliable-proxy-providers\/\" target=\"_blank\" rel=\"noreferrer noopener\">proxy<\/a> execution through trusted Windows utilities, often bypassing application whitelisting and antivirus detection. <\/p>\n<p>Once executed, the malware disables Windows Defender by adding broad file extension exclusions and specific directory exclusions, ensuring subsequent payloads remain undetected.<\/p>\n<p>The final payload is a customized variant of <a href=\"https:\/\/cybersecuritynews.com\/dcrat-subscriptions-for-5\/\" target=\"_blank\" rel=\"noreferrer noopener\">DCRat<\/a>, a remote access trojan capable of extensive system compromise. The RAT establishes persistence using internet shortcut files placed in the Windows startup folder, disguised as legitimate system utilities. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiDR_sE24_JKQy9Mdx3zgMvtNAoIl-s2sFqte3JVlMLAWch696KjD9kCR7GzNG4j2nz6Vo-mls3AP1DoJY5RXog88MM3wcNwSuWdW-1CtoocTvUjwpOd7uc2U9ukelBoctQrzLvJ4AAUWL8jUQjJH2HwR0NsiIKaLbLpO3XAhEjnriwc3dhYQgnMn7rQ5g\/s16000\/V.proj%2520%28Source%2520-%2520Securonix%29.webp?ssl=1\" alt=\"V.proj (Source - Securonix)\"><figcaption class=\"wp-element-caption\">V.proj (Source \u2013 Securonix)<\/figcaption><\/figure>\n<\/div>\n<p>Upon connection to command and control servers, the malware collects comprehensive system information including hardware identification, operating system details, installed antivirus software, and active window titles.<\/p>\n<p>The malware\u2019s capabilities include <a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-using-malicious-scripts-combining-beavertail-and-ottercookie-for-keylogging\/\" target=\"_blank\" rel=\"noreferrer noopener\">keylogging<\/a>, process injection into legitimate system binaries like aspnetcompiler.exe, and downloading additional malicious payloads. <\/p>\n<p>The presence of Cyrillic language artifacts and Russian debugging strings strongly indicates Russian-speaking threat actors. Organizations should implement rigorous user awareness training regarding click-fix tactics and monitor suspicious MSBuild.exe executions originating from non-standard directories to detect and prevent similar attacks.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-uses-fake-windows-bsod-screens\/\">New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-uses-fake-windows-bsod-screens\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code A sophisticated malware campaign called PHALTBLYX has emerged, combining social engineering deception with advanced evasion techniques to compromise hospitality sector organizations. The attack chain begins with phishing emails impersonating Booking.com, featuring urgent reservation cancellation alerts with large financial charges displayed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9669","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9669"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9669"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9669\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}