Cybercrooks book a stay in hotel email inboxes to trick staff into spilling credentials
ID: 8b672c7b-0afb-5ebd-a5e4-c6efad0174ed
STIX ID: report--8b672c7b-0afb-5ebd-a5e4-c6efad0174ed
Feed Name: The Register (Security)
Researchers (Sophos and Secureworks) have observed a targeted phishing campaign against hotel staff that leverages emotionally charged and time-sensitive emails to coerce victims into opening password-protected archives hosted on cloud services; these archives contain large, digitally signed executables that hide credential-stealing malware (variants of RedLine and Vidar). Attackers use harvested hotel admin credentials to access Booking.com partner portals and directly defraud customers by requesting payment details, with activity observed since at least March 2023 and resulting in confirmed customer losses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
