logo

Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware

ID: f2910445-e021-5f8c-aec1-b31de10181aa

STIX ID: report--f2910445-e021-5f8c-aec1-b31de10181aa

Feed Name: Microsoft Security

Threat Score
72/100

Date Published: 2025-03-13

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence and Microsoft Security Experts

...
...

Microsoft Threat Intelligence details an ongoing Storm-1865 phishing campaign (active since Dec 2024 and observed into Feb 2025) that impersonates Booking.com and uses the ClickFix social-engineering method to trick hospitality-sector staff into pasting and running commands (via mshta.exe) which fetch multiple credential- and payment‑stealing malware families; the report includes indicators (C2 IPs and SHA-256 hashes), detection hunts, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.