Urgent Alert: Booking.com Phishing Scam Uses “ClickFix” Trick to Deploy Dangerous Malware Against Hospitality Workers

Urgent Alert: Booking.com Phishing Scam Uses

# Booking.com Phishing Campaign Targets Hospitality Workers with Advanced Social Engineering

Microsoft security researchers have identified an ongoing phishing campaign targeting hospitality industry employees who use Booking.com. The campaign, attributed to a threat group known as “Storm-1865,” employs sophisticated ClickFix social engineering tactics to deploy various malware, including information stealers and remote access trojans (RATs).

## How the Attack Works

The attackers send convincing emails impersonating Booking.com communications, such as:
– Guest inquiries about negative reviews
– Requests from potential clients
– Account verification alerts

These emails contain either PDF attachments with embedded links or buttons directing victims to fake CAPTCHA pages. When users attempt to solve these CAPTCHAs, malicious code is secretly copied to their clipboard. Victims are then instructed to open the Windows Run command and paste the clipboard contents, unknowingly executing harmful commands.

The malicious code launches an mshta.exe command that downloads various malware, including:
– XWorm
– Lumma Stealer
– VenomRAT
– AsyncRAT
– Danabot
– NetSupport RAT

## The Attackers’ Goal

The primary objective is to hijack employee accounts on the Booking.com platform to steal:
– Customer payment details
– Personal information
– Credentials for fraudulent use

This stolen data could potentially be used to launch secondary attacks targeting hotel guests.

## Protection Recommendations

Microsoft advises users to:
– Verify sender email addresses carefully
– Be cautious of urgent action requests
– Watch for typographical errors in communications
– Check Booking.com account status directly through the official website rather than following email links

The campaign, which began in December 2024, continues to pose a significant threat to the hospitality sector.

Share This Article