Threat Actor Impersonates Booking.com in Phishing Scheme
ID: 37a2b12f-bfcf-57a9-a0c9-d59e5145bdc1
STIX ID: report--37a2b12f-bfcf-57a9-a0c9-d59e5145bdc1
Feed Name: Dark Reading
Date Published: 2025-03-14
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
Microsoft disclosed an ongoing global phishing campaign by the actor Storm-1865 that uses a social-engineering technique dubbed "ClickFix" to impersonate Booking.com; victims are lured to paste commands into the Windows Run dialog from a fake verification page, causing the download of multiple malware families with credential- and financial-data-stealing capabilities targeting the hospitality sector across multiple regions. Microsoft and Booking.com advise users to verify senders, check URLs, and follow security hygiene while administrators should limit privileges to reduce impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
