In a cunning cyberattack, Booking.com customers are being targeted by a sophisticated malware campaign delivering Agent Tesla through PDF attachments in fraudulent emails. This scam, masquerading as a refund notification, entices recipients to open an attached PDF supposedly containing their card statement. However, this document harbors malicious scripts and embedded URLs designed to compromise systems.
Unveiling the Deceptive Scheme
Upon opening the malicious PDF, users are lured into clicking embedded links that download an obfuscated JavaScript. This script is just the beginning of a multi-layered attack that proceeds to download a PowerShell script equipped with advanced obfuscation techniques. The PowerShell script employs several defense evasion tactics, modifies system registries, disables antivirus protections, and ultimately deploys a .dll file associated with the notorious Agent Tesla malware family. Known for…
















