A recent phishing campaign has raised alarms among cybersecurity professionals after it impersonated Booking.com to deliver a suite of credential-stealing malware.
First detected in December 2024 and persisting into early 2025, the threat targets hospitality organizations across North America, Oceania, Asia, and Europe. Using an insidious social engineering method called ClickFix, attackers manipulate users into unwittingly executing malicious commands, leading to extensive data theft and financial fraud.
The anatomy of the attack
The campaign employs a multi-layered approach, starting with deceptive emails that appear to originate from Booking.com. Here’s what comes next:
- These emails lure victims with urgent requests, from resolving guest review issues to verifying account information.
- The phishing…































