Major phishing attacks hit hotels with ingenious new scam that also spreads dangerous malware


  • ClickFix phishing campaign targets hotels and guests with PureRAT malware
  • Attackers Exploit Compromised Booking.com Accounts and Sell Stolen Credentials on Dark Web Forums
  • Guests tricked into fake Booking/Expedia sites and lost login and payment card data

Hotels and their guests are being targeted by a highly sophisticated ClickFix campaign that aims to deliver dangerous malware, steal login credentials and conduct fraudulent transfer transactions, experts have warned.

Cybersecurity researchers Sekoia revealed that the attackers would first use random, compromised email accounts to send hotels and various Booking.com account holders a phishing message. The link in the message triggers a redirect chain that ultimately leads to a fake reCAPTCHA challenge designed to trick victims into downloading and installing a remote access Trojan called PureRAT.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top