Summary
Key Points:
- A new ClickFix social engineering campaign targets the hospitality sector in Europe, using fake Windows BSOD screens to trick users into executing malware.
- The attack impacts hospitality firms by compromising systems through a remote access Trojan (DCRAT), enabling data theft and lateral movement within networks.
- Recommended actions include user training on recognizing phishing attempts, implementing email filtering to block malicious links, and monitoring for unusual PowerShell activity.
Technical Details: The campaign utilizes phishing emails impersonating Booking.com to direct victims to a fake website that prompts them to run malicious PowerShell commands. The malware (staxs.exe) is a DCRAT variant that establishes persistence and communicates with a command-and-control server.
MITRE ATT&CK Techniques:
- T1566.001 - Phishing: Spearphishing Attachment (Initial Access)
- T1059.001 - Command and Scripting Interpreter: PowerShell (Execution)
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1105 - Ingress Tool Transfer (Command and Control)
- T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys (Persistence)
IOCs Mentioned:
- low-house[.]com (malicious domain)
- staxs.exe (malware filename)
Join the discussion — sign up to comment, upvote, and save articles.