logo

Fake Booking.com ClickFix attack abuses Cloudflare verification to deliver malware

ID: 95549556-14fb-5225-9a75-b1f920485a59

STIX ID: report--95549556-14fb-5225-9a75-b1f920485a59

Feed Name: ThreatLocker Blog

Threat Score
70/100

Date Published: 2026-01-23

Date Updated: 2026-05-01

...
...

ThreatLocker documents an active ClickFix campaign that lures users with fake Cloudflare/Turnstile pages on malicious booking.com subdomains, coercing victims to paste Run/PowerShell commands which execute a JavaScript downloader (lwiiiqzxxgaghaas.js) that installs Node.js, extracts a final payload (Jghiiznajjdvlad.js), establishes persistence via a registry Run key, and connects over Tor to receive commands, transfer files, and execute arbitrary code; the report includes extensive IoCs (SHA-256 hashes, domains, IPs) and identifies related malicious GitHub repositories hosting additional tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.