Booking.com Phishing Campaign Targeting Hotels and Customers
ID: 027dd66a-9cd3-57aa-abc2-81ada143bdac
STIX ID: report--027dd66a-9cd3-57aa-abc2-81ada143bdac
Feed Name: Sekoia.com
**Executive summary:** Sekoia.io analysts describe an ongoing global campaign (active since at least April 2025) targeting hospitality providers by compromising booking-platform accounts via a ClickFix social-engineering chain that delivers PureRAT through PowerShell, enabling credential theft and subsequent customer-targeted banking phishing; the report includes technical TTPs, detection guidance, numerous IOCs, and evidence of a mature underground market trading Booking.com extranet logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
