A team of cyber security researchers has identified an advanced phishing campaign utilizing a previously unknown threat actor, PHALT#BLYX, targeting businesses within the European Hotel Industry. Cyber criminals operate a ClickFix (style) lure based on notifications from Booking (dot) Com, which lead victims to execute PowerShell commands that trigger the installation of a remote access trojan (RAT) known as DCRat.
The initial contact for this attack is an email that states the recipient has received an unexpected cancellation of a reservation. By clicking on the link in the email, the recipient is sent to a fake Booking.com website. After going through a CAPTCHA challenge, the recipient is redirected to a fake "blue screen of death," and is then instructed to execute a command via the Windows Run dialog to download an MSBuild project file from a server located at 2fa-bns[dot]com.
The MSBuild Project file is executed using MSBuild.exe, then creating persistence via the use of the DCRat which is able to model the behaviour of Microsoft Defender and to perform automatic launching. DCRat is built with the ability to use plugin applications to do things like log keystrokes, execute commands, etc., and there are also plugins that can provide payloads for things like mining cryptocurrencies.
According to the researchers, the campaign takes advantage of "living-off-the-land" techniques, where existing binaries on a compromised system are abused to evade detection by security tools and maintain persistence on the system. In addition, the emails sent to potential victims contain room charge receipts in Euros, which demonstrates that the campaign has been specifically targeting European hotels and other hospitality-related organizations.
The use of Russian language references within the accompanying MSBuild file indicates that Russian hacker groups may be behind the distribution of DCRat.
Organizations should educate their employees on how to identify phishing attempts. Organizations should also monitor all PowerShell activity and ensure that all users are using endpoint protection solutions, as well as verify that any notifications received appear legitimate before acting upon them.
Source: The Hacker News