Major phishing attack hits hotels with ingenious new scam that also spreads dangerous malware


  • ClickFix phishing campaign targets hotels and guests with PureRAT malware
  • Attackers exploit compromised Booking.com accounts and sell stolen credentials on Dark Web forums.
  • Customers trapped on fake Booking/Expedia sites, losing their login and payment card details

Hotels and their guests are being targeted by a highly sophisticated ClickFix campaign aimed at spreading dangerous malware, stealing login credentials and carrying out fraudulent electronic transactions, experts have warned.

Cybersecurity researchers Sekoia revealed that attackers would first use random, compromised email accounts to send a phishing message to hotels and individual Booking.com account holders. The link in the message triggers a redirect chain that ultimately leads to a fake reCAPTCHA challenge, designed to trick victims into downloading and installing a remote access Trojan called PureRAT.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top