logo

Microsoft Research Reveals – Phishing Campaign Impersonates Booking(.)com, Delivers a Suite of Credential-Stealing Malware

ID: 6879dcd5-89d2-5e53-9e0a-ab97d54aadb7

STIX ID: report--6879dcd5-89d2-5e53-9e0a-ab97d54aadb7

Feed Name: infostealers.com

Threat Score
70/100

Date Published: 2025-03-13

Date Updated: 2026-06-07

Author: InfoStealers

...
...

Microsoft Threat Intelligence documents an ongoing global phishing campaign (Storm-1865) impersonating Booking.com that leverages a ClickFix social-engineering flow to coerce hospitality employees into running commands which invoke mshta.exe to download various credential- and payment‑stealing malware families; the report supplies IOCs, detection guidance, hunting queries, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.