Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware
ID: f2910445-e021-5f8c-aec1-b31de10181aa
STIX ID: report--f2910445-e021-5f8c-aec1-b31de10181aa
Feed Name: Microsoft Security
Date Published: 2025-03-13
Date Updated: 2026-04-28
Author: Microsoft Threat Intelligence and Microsoft Security Experts
Microsoft Threat Intelligence details an ongoing Storm-1865 phishing campaign (active since Dec 2024 and observed into Feb 2025) that impersonates Booking.com and uses the ClickFix social-engineering method to trick hospitality-sector staff into pasting and running commands (via mshta.exe) which fetch multiple credential- and payment‑stealing malware families; the report includes indicators (C2 IPs and SHA-256 hashes), detection hunts, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
