• ‘ClickFix’ Phishing Scam Impersonates Booking.com to Target Hospitality

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » ‘ClickFix’ Phishing Scam Impersonates Booking.com to Target Hospitality

    Author
    Topic
    #2755672

    https://www.infosecurity-magazine.com/news/clickfix-phishing-scam-booking/

    A sophisticated ‘ClickFix’ phishing campaign is impersonating Booking.com to target hospitality firms with multiple infostealing malware, enabling financial fraud and theft.

    The ongoing campaign, which began in December 2024, has been attributed by Microsoft Threat Intelligence to a threat cluster known as Storm-1865.

    The attackers use a social engineering technique called ClickFix to specifically target individuals in hospitality organizations in North America, Oceania, South and Southeast Asia, and Europe, which are likely to work with Booking.com, an online travel agency.

    ClickFix sees threat actors use fake error messages that instruct users to fix issues copying, pasting and launching commands that eventually result in the download of malware.

    The technique can bypass conventional and automated security features as the user infects themselves…

    https://www.bleepingcomputer.com/news/security/clickfix-attack-delivers-infostealers-rats-in-fake-bookingcom-emails/

    1 user thanked author for this post.
    Reply To: ‘ClickFix’ Phishing Scam Impersonates Booking.com to Target Hospitality

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: