Phishing Campaigns “I Paid Twice” Targeting Booking.com Hotels and Customers
ID: 75d7a4a7-75f8-5e24-bd3b-152811eb8b43
STIX ID: report--75d7a4a7-75f8-5e24-bd3b-152811eb8b43
Feed Name: Sekoia.io Blog
Date Published: 2025-11-06
Date Updated: 2026-04-29
Author: Jeremy Scion, Quentin Bourgue and Sekoia TDR
**I Paid Twice** describes a global phishing and malware campaign targeting hotel booking-extranet accounts and their customers: attackers used compromised Booking.com emails and ClickFix social engineering to trick administrators into executing PowerShell that stages PureRAT (fileless DLL side-loading), enabling credential theft, sale of extranet logs on cybercrime forums, and targeted banking phishing of guests; the report includes detailed TTPs, IOCs, detection queries (SOL/Sigma/Sysmon), and ecosystem analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
