logo

Phishing Campaigns “I Paid Twice” Targeting Booking.com Hotels and Customers

ID: 75d7a4a7-75f8-5e24-bd3b-152811eb8b43

STIX ID: report--75d7a4a7-75f8-5e24-bd3b-152811eb8b43

Feed Name: Sekoia.io Blog

Threat Score
78/100

Date Published: 2025-11-06

Date Updated: 2026-04-29

Author: Jeremy Scion, Quentin Bourgue and Sekoia TDR

...
...

**I Paid Twice** describes a global phishing and malware campaign targeting hotel booking-extranet accounts and their customers: attackers used compromised Booking.com emails and ClickFix social engineering to trick administrators into executing PowerShell that stages PureRAT (fileless DLL side-loading), enabling credential theft, sale of extranet logs on cybercrime forums, and targeted banking phishing of guests; the report includes detailed TTPs, IOCs, detection queries (SOL/Sigma/Sysmon), and ecosystem analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.