Urgent Alert: Hospitality Sector Under Attack – Microsoft Exposes Sophisticated Booking.com Phishing Scam Using ClickFix Technique


# Hospitality Sector Targeted by Sophisticated Booking.com Phishing Campaign

Microsoft has uncovered a sophisticated phishing campaign targeting the hospitality industry by impersonating Booking.com. The operation, tracked as Storm-1865, began in December 2024 and employs the increasingly popular “ClickFix” social engineering technique to deliver credential-stealing malware.

## The Attack Strategy

The campaign specifically targets hospitality organizations across North America, Oceania, Asia, and Europe—particularly staff likely to interact with Booking.com. The attack begins with malicious emails about supposed negative guest reviews, requesting feedback from recipients.

These emails contain links or PDF attachments that appear to direct users to Booking.com but instead lead to a fake CAPTCHA verification page overlaid on a convincing Booking.com background. This deceptive design creates a false sense of security for victims.

## The ClickFix Technique

The fake CAPTCHA page employs the ClickFix method, which instructs users to:
1. Use a keyboard shortcut to open Windows Run
2. Paste and execute a command that the webpage has secretly added to their clipboard

This command leverages the legitimate mshta.exe binary to download various malware payloads, including XWorm, Lumma Stealer, VenomRAT, AsyncRAT, Danabot, and NetSupport RAT.

## Broader Implications

Microsoft notes that Storm-1865 previously targeted e-commerce platform users with fraudulent payment pages. The adoption of ClickFix represents a tactical evolution designed to bypass conventional security measures.

The effectiveness of ClickFix has led to its adoption by various threat actors, including Russian and Iranian nation-state groups like APT28 and MuddyWater. Group-IB reports that the technique “capitalizes on human behavior” by presenting a plausible solution to a perceived problem, shifting execution responsibility to the user and bypassing automated defenses.

Other ClickFix campaigns have utilized fake CAPTCHA verifications, Google reCAPTCHA challenges, and Windows-themed sites to deploy various malware, particularly Lumma Stealer.

Separately, researchers have identified threat actors using AI-generated GitHub repositories to distribute Lumma Stealer via “SmartLoader,” exploiting the trust associated with popular platforms for malware distribution.

Share This Article