Booking.com confirms phsihing attack against customers.
An infostealer malware campaign has been identified by Microsoft Threat Intelligence that targets victims with fake CAPTCHA tests to get users to execute malicious code to ultimately compromise Booking.com partner and customer accounts and financial data.
Booking.com Users Targeted By Storm-1865 Group To Steal Credentials
The Booking.com phishing campaign that has been unearthed by Microsoft threat Intelligence analysts is known to employ the ClickFix threat, something I have reported in before, which in turn uses fake CAPTCHA tests as a method of executing malicious code.
Specifically targeting individuals, mostly working in hospitality, funnily enough, the campaign has a broad reach: North America, Oceania, South and Southeast Asia, along with Northern, Southern, Eastern, and Western Europe. The common link being that…































