Massive Phishing Attack Impersonate as Travel Brands Attacking Users with 4,300 Malicious Domains
ID: fe8ecbe7-38b6-541f-941f-82569bdaa479
STIX ID: report--fe8ecbe7-38b6-541f-941f-82569bdaa479
Feed Name: cybersecurityNews.com
Threat Score
A widespread phishing campaign (started Feb 2025) is targeting travelers and hotel guests using more than 4,300 spoofed domains and a multi-stage redirection chain to host convincing fake booking pages that capture payment card details; the kit supports 43 languages, real-time keystroke exfiltration, Luhn validation, fake Cloudflare CAPTCHA and automated social-engineering chat, and appears tied to a Russian-speaking operator.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
