Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Major phishing attack hits hotels with ingenious new scam that also spreads dangerous malware

Tech Wavo by Tech Wavo
November 12, 2025
in Computers
0



  • ClickFix phishing campaign targets hotels and guests with PureRAT malware
  • Attackers exploit compromised Booking.com accounts and sell stolen credentials on dark web forums
  • Guests tricked into fake Booking/Expedia sites, losing login and payment card data

Hotels and their guests are being targeted by a highly sophisticated ClickFix campaign aiming to deliver dangerous malware, steal login credentials, and make fraudulent wire transactions, experts have warned.

Cybersecurity researchers Sekoia revealed the attackers would first use random, compromised email accounts to mail hotels and different Booking.com account holders with a phishing message. The link in the message triggers a redirection chain that ultimately leads to a fake reCAPTCHA challenge, designed to get the victims to download and install a remote access trojan called PureRAT.

The attackers are careful to make sure they’re targeting the right people, Sekoia explained. On dark web forums, such as LolzTeam, they purchase information about Booking.com establishment administrators and, in some scenarios, even offer a cut in exchange for valid contact information.


You may like

Stealing credit card data

“Booking.com extranet accounts play a crucial role in fraudulent schemes targeting the hospitality industry,” Sekoia’s researchers explained.

“Consequently, data harvested from these accounts has become a lucrative commodity, regularly offered for sale in illicit marketplaces.”

PureRAT is capable of all sorts of nasties – from granting remote access, to allowing attackers to control the mouse and the keyboard. It can also control the webcam and microphone to capture both sound and video, can log keystrokes, and upload/download additional files.

The attackers seem to be using it, however, to map out the hotel’s customers. Then, they start mailing them, as well as sending personalized WhatsApp messages, containing real reservation details to make the scams appear legitimate.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

These messages also contain phishing links that redirect the victims to fake Booking or Expedia sites where, if the recipients log in, their credentials – as well as credit card information – is nabbed.

We don’t know how many hotels, or people, were compromised by this campaign, however Sekoia says it has been active since at least April 2025, and operational as of early October 2025.


Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Previous Post

An AI executive’s dire warnings about the future are chilling – but his solution is worse than the problem

Next Post

Leading AI companies keep leaking their own information on GitHub

Next Post
What is Model Context Protocol (MCP) and why is it crucial for AI development?

Leading AI companies keep leaking their own information on GitHub

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Samsung Galaxy A17 Price Cut to £139 for Black Friday

by Tech Wavo
November 12, 2025
0
Samsung Galaxy A17 Price Cut to £139 for Black Friday
Mobile

Black Friday deals are flowing freely weeks ahead of the day itself and Samsung’s brand-new budget Android phone is even...

Read more

WUBEN X1Pro Flashlight : 13,000 Lumens of Power and Durability

by Tech Wavo
November 12, 2025
0
WUBEN X1Pro Flashlight : 13,000 Lumens of Power and Durability
Gadgets

What if the flashlight in your hand could outshine car headlights, double as a powerbank, and withstand the harshest environments,...

Read more

A Coding Implementation to Build and Train Advanced Architectures with Residual Connections, Self-Attention, and Adaptive Optimization Using JAX, Flax, and Optax

by Tech Wavo
November 12, 2025
0
A Coding Implementation to Build and Train Advanced Architectures with Residual Connections, Self-Attention, and Adaptive Optimization Using JAX, Flax, and Optax
News

In this tutorial, we explore how to build and train an advanced neural network using JAX, Flax, and Optax in...

Read more

Lenovo Go USB-C laptop power bank review: tame bag clutter thanks to a built-in charging cable

by Tech Wavo
November 12, 2025
0
Lenovo Go USB-C laptop power bank review: tame bag clutter thanks to a built-in charging cable
Computers

Why you can trust TechRadar We spend hours testing every product or service we review, so you can be sure...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock