Skip to content
Search

Latest Stories

Microsoft warns hotels of phishing campaign

The hackers pose as Booking.com to deploy malware for fraud and theft

Microsoft warns of phishing scam impersonating Booking.com to target hotels with credential-stealing malware.

Microsoft recently warned of an ongoing phishing campaign by threat actor Storm-1865, which targets hospitality organizations across North America, Europe, Oceania, and South and Southeast Asia by impersonating Booking.com and using the ClickFix technique to deliver credential-stealing malware.

Photo credit: iStock

Microsoft Warns Hotels: Protect Against Booking.com Phishing Scam

MICROSOFT RECENTLY WARNED of a phishing campaign targeting the hospitality sector, where attackers impersonate Booking.com and use the ClickFix social engineering technique to deliver credential-stealing malware. The tech giant tracks the threat actor, Storm-1865, which has targeted hospitality organizations across North America, Europe, Oceania, and South and Southeast Asia in an ongoing campaign.

The hackers deploy info-stealing malware for financial fraud and theft through fake emails impersonating the agency, Microsoft said in a blog post.


“Starting in December, leading up to some of the busiest travel days, Microsoft Threat Intelligence identified a phishing campaign that impersonates online travel agency Booking.com and targets organizations in the hospitality industry,” Microsoft said. “The campaign uses ClickFix to deliver multiple credential-stealing malware strains to facilitate financial fraud and theft. As of February, the campaign is ongoing.”

Microsoft said the attack specifically targets individuals in hospitality organizations in North America, Oceania, South and Southeast Asia, and Europe who are likely to work with Booking.com.

“The phishing emails claim to be from Booking.com and reference negative reviews, account verification, promotions, or guest requests,” the blog post stated. “They include links or PDFs leading to fake Booking.com sites that use ClickFix to trick users into downloading malware. ClickFix displays an error or verification prompt, instructing users to copy an unseen string, paste it into a Windows terminal, and execute it.”

“Unfortunately, phishing attacks by criminal organizations pose a significant threat to many industries,” Booking.com said, according to SecurityWeek. “While Booking.com’s systems have not been breached, we are aware that some accommodation partners and customers have been impacted by phishing attacks from professional criminals attempting to take over their local computer systems with malware.”

Microsoft noted that Storm-1865 has been active since 2023, targeting hotel guests and e-commerce users with phishing campaigns.

“The number of accommodations affected by this scam is a small fraction of those on our platform, and we continue to make significant investments to limit the impact on our customers and partners,” Booking.com said.

In Storm-1865 attacks observed by Microsoft, victims are prompted to check a box to prove they are human and then press Windows + R, Ctrl + V, and Enter. “Checking the box copies a command to the clipboard, and the key presses open the Windows Run window, paste the command, and execute it,” Microsoft Threat Intelligence found. “The command downloads and runs malware such as XWorm, Lumma, VenomRAT, AsyncRAT, Danabot or NetSupport RA.”

“All these payloads include capabilities to steal financial data and credentials for fraudulent use, which is a hallmark of Storm-1865 activity,” Microsoft said. “The addition of ClickFix to this threat actor’s tactics, techniques, and procedures shows how Storm-1865 is evolving its attack chains to bypass conventional security measures.”

Meanwhile, Booking.com said it is committed to helping partners and customers stay protected.

“We provide ongoing cybersecurity education and resources to our partners to enhance their defenses against such threats,” Booking.com told SecurityWeek.

In 2022, InterContinental Hotels Group franchisees sued the company over a cyberattack that disrupted booking channels, alleging IHG ignored prior breach warnings. The attack affected reservations, customer care centers, and internal systems, including Merlin and the Help Desk.

More for you

Marriott associate using PathSpot Hand Scanner to validate handwashing in a hotel kitchen.

Marriott implements new hygiene tech

How PathSpot’s Technology Enhances Marriott’s Kitchen Safety and Efficiency

MARRIOTT INTERNATIONAL IS contracting with PathSpot Technologies Inc. to implement its real-time hygiene management and digital kitchen system, which includes handwashing validation and equipment monitoring. Marriott properties use PathSpot’s Hand Scanner and logging system to create handwashing records and ensure compliance with operating procedures.

PathSpot’s sensors use visual, audible and electronic cues to instantly alert associates when contamination is detected, prompting additional handwashing, the companies said in a statement.

Keep ReadingShow less
Revival Hotels and Stayntouch cloud PMS partnership announcement 2025

Revival Hotels implements new PMS

How Revival Hotels Enhances Operations with Stayntouch’s Cloud PMS

HOTEL MANAGEMENT FIRM Revival Hotels is working with Stayntouch to provide its cloud-based property management systems to Revival’s independent portfolio. Revival is led by Founder and CEO Saxton Sharad.

Revival will receive automated software with flexibility and an interface its team can adopt to improve daily operations, the companies said in a joint statement.

Keep ReadingShow less
Apaleo team launching Agent Hub AI marketplace in 2025
iStock

Apaleo launches AI agent marketplace

What Is Apaleo Agent Hub?

APALEO, A PROPERTY management platform, recently launched Agent Hub, which it calls “the first-ever AI agent marketplace for hospitality.” The platform enables industry collaboration by connecting property managers, hoteliers, developers and service providers to accelerate AI adoption.

Agent Hub lets hospitality players select AI solutions suited to their needs and integrate them without costly system overhauls, Apaleo said in a statement.

Keep ReadingShow less
OYO G6 હોસ્પિટાલિટીના ડિજિટલ અપગ્રેડ માટે $10 મિલિયન રોકશે

OYO G6 હોસ્પિટાલિટીના ડિજિટલ અપગ્રેડ માટે $10 મિલિયન રોકશે

હોસ્પિટલિટી ટેકનોલોજી ફર્મ OYO ઉનાળા પહેલા એપ્લિકેશન્સમાં ચાર ગણો વધારો કરવાનો લક્ષ્ય રાખીને G6 હોસ્પિટાલિટીની ડિજિટલ સંપત્તિઓને વધારવા માટે $10 મિલિયનનું રોકાણ કરવાનું લક્ષ્ય રાખે છે. કંપની ડિજિટલ ટાર્ગેટિંગનો ઉપયોગ કરશે, જે Google અને Microsoft સાથે સીધી ભાગીદારી દ્વારા હાઈ ઇન્ટેન્ટ ગ્રાહકો પર ધ્યાન કેન્દ્રિત કરશે.

આ રોકાણ ડેટા-આધારિત ડિજિટલ ઝુંબેશને ભંડોળ પૂરું પાડશે, જેથી ગ્રાહકો બુકિંગ રૂપાંતરણ અને ફ્રેન્ચાઇઝ ભાગીદાર મૂલ્યને વધારવાના હેતુથી રહેઠાણની શોધમાં સક્રિય રીતે પહોંચી શકે, એમ G6 હોસ્પિટાલિટીએ એક નિવેદનમાં જણાવ્યું હતું.

Keep ReadingShow less
OYO invests $10M to enhance G6 Hospitality’s digital platform, improving website, app, and direct bookings for better guest experience

OYO commits $10 million to G6 Hospitality’s digital upgrade

OYO’s $10M Investment to Enhance G6 Hospitality’s Digital Growth

HOSPITALITY TECHNOLOGY FIRM OYO aims to invest $10 million to enhance G6 Hospitality’s digital assets, including its website and app, targeting a quadruple increase in apps before summer. The company will use digital targeting, focusing on high-intent customers through direct partnerships with Google and Microsoft.

The investment will fund data-driven digital campaigns to reach customers actively searching for accommodations with an aim toward boosting booking conversions and franchise partner value, G6 Hospitality said in a statement.

Keep ReadingShow less