logo

Cybercrooks book a stay in hotel email inboxes to trick staff into spilling credentials

ID: 8b672c7b-0afb-5ebd-a5e4-c6efad0174ed

STIX ID: report--8b672c7b-0afb-5ebd-a5e4-c6efad0174ed

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2023-12-20

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers (Sophos and Secureworks) have observed a targeted phishing campaign against hotel staff that leverages emotionally charged and time-sensitive emails to coerce victims into opening password-protected archives hosted on cloud services; these archives contain large, digitally signed executables that hide credential-stealing malware (variants of RedLine and Vidar). Attackers use harvested hotel admin credentials to access Booking.com partner portals and directly defraud customers by requesting payment details, with activity observed since at least March 2023 and resulting in confirmed customer losses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.