logo

Booking.com phish uses fake CAPTCHAs to trick hotel staff into downloading malware

ID: 8dd9b4d5-a2fa-5732-b104-80988f864b43

STIX ID: report--8dd9b4d5-a2fa-5732-b104-80988f864b43

Feed Name: Malwarebytes Blog

Threat Score
65/100

Date Published: 2025-03-26

Date Updated: 2026-04-28

...
...

ThreatDown and Malwarebytes report a phishing campaign that sends spoofed Booking.com emails to hotel staff; when recipients copy-and-paste the provided link they land on a fake CAPTCHA page that instructs them to paste an mshta command into Windows Run, which then fetches and executes an information-stealing Trojan aimed at stealing guest payment and personal data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.