logo

ClickFix attack delivers infostealers, RATs in fake Booking.com emails

ID: bb8d4ecf-c30b-5bd9-8045-4e2ab56560ee

STIX ID: report--bb8d4ecf-c30b-5bd9-8045-4e2ab56560ee

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-03-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft warns of an ongoing phishing campaign impersonating Booking.com that leverages ClickFix fake-CAPTCHA social engineering to trick hotel and travel staff into pasting and executing an mshta command; that command fetches HTML/PowerShell/PE payloads installing various infostealers and RATs (Lumma, XWorm, VenomRAT, AsyncRAT, Danabot, NetSupport) to hijack accounts and steal customer payment and personal data, and the activity is attributed to the group tracked as Storm-1865.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.