← Back to news

ClickFix attack uses fake Windows BSOD screens to push malware

BleepingComputer05/01/2026, 21:16
Read full article →

Summary

AI-Generated

Key Points:

  • A new ClickFix social engineering campaign targets the hospitality sector in Europe, using fake Windows BSOD screens to trick users into executing malware.
  • The attack impacts hospitality firms by compromising systems through a remote access Trojan (DCRAT), enabling data theft and lateral movement within networks.
  • Recommended actions include user training on recognizing phishing attempts, implementing email filtering to block malicious links, and monitoring for unusual PowerShell activity.

Technical Details: The campaign utilizes phishing emails impersonating Booking.com to direct victims to a fake website that prompts them to run malicious PowerShell commands. The malware (staxs.exe) is a DCRAT variant that establishes persistence and communicates with a command-and-control server.

MITRE ATT&CK Techniques:

  • T1566.001 - Phishing: Spearphishing Attachment (Initial Access)
  • T1059.001 - Command and Scripting Interpreter: PowerShell (Execution)
  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1105 - Ingress Tool Transfer (Command and Control)
  • T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys (Persistence)

IOCs Mentioned:

  • low-house[.]com (malicious domain)
  • staxs.exe (malware filename)

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.