
Microsoft security researchers have identified an ongoing phishing campaign targeting hospitality industry employees who use Booking.com. The campaign, attributed to a threat group known as “Storm-1865,” employs sophisticated ClickFix social engineering tactics to deploy various malware, including information stealers and remote access trojans (RATs).
## How the Attack Works
The attackers send convincing emails impersonating Booking.com communications, such as:
– Guest inquiries about negative reviews
– Requests from potential clients
– Account verification alerts
These emails contain either PDF attachments with embedded links or buttons directing victims to fake CAPTCHA pages. When users attempt to solve these CAPTCHAs, malicious code is secretly copied to their clipboard. Victims are then instructed to open the Windows Run command and paste the clipboard contents, unknowingly executing harmful commands.
The malicious code launches an mshta.exe command that downloads various malware, including:
– XWorm
– Lumma Stealer
– VenomRAT
– AsyncRAT
– Danabot
– NetSupport RAT
## The Attackers’ Goal
The primary objective is to hijack employee accounts on the Booking.com platform to steal:
– Customer payment details
– Personal information
– Credentials for fraudulent use
This stolen data could potentially be used to launch secondary attacks targeting hotel guests.
## Protection Recommendations
Microsoft advises users to:
– Verify sender email addresses carefully
– Be cautious of urgent action requests
– Watch for typographical errors in communications
– Check Booking.com account status directly through the official website rather than following email links
The campaign, which began in December 2024, continues to pose a significant threat to the hospitality sector.
