Microsoft Threat Intelligence has revealed a phishing campaign that impersonates Booking.com, initiated in December 2024, targeting hospitality organizations in multiple regions. Attackers send deceptive emails with malicious links or attachments that lead to fake Booking.com pages. Using a technique called “ClickFix,” victims unknowingly execute commands to download malware, including XWorm and VenomRAT, allowing theft of sensitive data.

Phishing Campaign Impersonates Booking.com, Plants Malware
Cybersecurity professionals have raised concerns over a new phishing campaign that imitates Booking.com to plant credential-stealing malware. The threat, first detected in December 2024, targets