BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Massive Phishing Campaign Targets Hotels with ClickFix Malware

Phishing Campaign Targets Hotels with PureRAT Malware via Fake Booking.com Pages and Spear-Phishing Tactics

  • A widespread phishing campaign is targeting hotel managers with ClickFix-style pages to steal credentials and deploy Malware.
  • The malware involved, PureRAT, allows remote control over infected systems including data theft and surveillance.
  • Attackers use compromised email accounts to send spear-phishing messages that mimic Booking.com and redirect victims to fraudulent sites.
  • Malicious actors also contact hotel customers via WhatsApp or email using real reservation details to steal payment card information.
  • A growing underground market sells stolen Booking.com accounts and uses automated tools to verify compromised credentials.

A large phishing campaign has targeted the hospitality sector since at least April 2025, using compromised email accounts to send malicious messages to multiple hotels worldwide. The attackers impersonate Booking.com in spear-phishing emails that redirect recipients to fake ClickFix-style web pages designed to harvest credentials and install malware.

- Advertisement -

The campaign deploys PureRAT, also known as zgRAT, a remote access trojan loaded through DLL side-loading. This malware enables extensive control over infected devices, including mouse and keyboard inputs, webcam and microphone recording, keylogging, file transfers, data exfiltration, and remote command execution. It also establishes persistence by adding registry keys and uses .NET Reactor for protection against reverse engineering.

Victims are tricked into following instructions on phishing pages that deploy a malicious PowerShell script. The script gathers system details and downloads an archive containing malware binaries. These pages often simulate reCAPTCHA challenges and adapt to the victim’s operating system, prompting them to open programs like the Windows Run dialog or macOS Terminal, sometimes copying malicious commands directly to the clipboard.

Beyond targeting hotel staff, attackers contact hotel customers via WhatsApp or email with legitimate reservation information. Customers are urged to verify their bookings by clicking links that lead to counterfeit Booking.com or Expedia sites aimed at stealing payment card data.

Threat actors obtain administrator details for Booking.com properties from criminal forums such as LolzTeam, sometimes offering payments based on profits. These credentials are sold in underground markets or used to send fraudulent emails. There are services advertised on platforms like Telegram offering access to Booking.com, Expedia, Airbnb, and Agoda account logs, which are manually checked using automated log checker tools costing as little as $40 to confirm credential validity.

- Advertisement -

According to Sekoia, the thriving cybercrime ecosystem and the use of Booking.com accounts as commodities have led to professionalization in this fraud model. Enhancements to the ClickFix social engineering tactic include embedded videos, countdown timers, user verification counters, and clipboard hijacking to increase effectiveness, as outlined by Push Security.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

EIP-8141 Frames: Pay Gas in Tokens on Ethereum

EIP-8141's Frame transactions split a transaction into validation, payment and execution steps, each an...

Zcash ETF launch sparks rally to 2016 high

ZCash (ZEC) surged to $1,249.28, its highest price since 2016, pushing market cap above...

JSCeal Malware Steals Crypto via Compiled V8 Bytecode

Cybersecurity researchers have unveiled JSCeal, a sophisticated compiled V8 JavaScript malware used to steal...

Fomo overtakes Pump.fun in daily revenue on Solana

Social trading platform Fomo generated $1.76 million in daily revenue on Friday, surpassing memecoin...

Inflation Data Looms Over Stocks & Crypto This Week

The US market will be closed on Monday for Labor Day, but the cryptocurrency...

Must Read

A Beginner’s Guide To Cryptocurrency Mining

Cryptocurrency is considered one of the most popular forms of financial assets today. Many of these digital assets operate within blockchain technology which works...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading