Connect with us

Hi, what are you looking for?

Technology

Phishing Attack Targets Hotels, Spreading PureRAT Malware

A sophisticated phishing campaign targeting hotels and their guests has emerged, deploying the dangerous PureRAT malware. The ClickFix operation has raised alarms among cybersecurity experts, who warn that both hotel staff and customers are at risk of losing sensitive information.

According to cybersecurity researchers from Sekoia, the ClickFix campaign initially involves hackers using compromised email accounts to send phishing messages to hotels and Booking.com users. These messages contain links leading to a deceptive website that mimics a legitimate reCAPTCHA challenge. Once victims engage with this site, they inadvertently download the remote access trojan known as PureRAT.

Malicious Tactics and Dark Web Connections

The attackers demonstrate a calculated approach by targeting specific individuals. They purchase data about Booking.com hotel administrators from dark web forums, such as LolzTeam, sometimes offering a financial incentive for valid contact information. The information obtained from Booking.com accounts is particularly valuable, as it plays a crucial role in fraudulent schemes within the hospitality sector.

“Data harvested from these accounts has become a lucrative commodity, regularly offered for sale in illicit marketplaces,” researchers from Sekoia noted. The malware itself allows attackers extensive control, including the ability to access webcams and microphones, log keystrokes, and manipulate files.

The ClickFix campaign appears to focus on mapping hotel customers. Once they gather sufficient information, the attackers send personalized emails and WhatsApp messages to customers, often referencing real reservation details to lend credibility to their scams. These communications also contain phishing links, which, when clicked, lead victims to counterfeit Booking or Expedia sites. If users enter their login credentials, both their account details and credit card information are at risk.

Ongoing Threats and Precautionary Measures

As of early October 2025, the ClickFix campaign has been operational since at least April 2025. While the full extent of the attack remains unclear, the potential for widespread compromise among hotels and guests is significant. Cybersecurity experts urge both the hospitality industry and consumers to remain vigilant against these types of cyber threats.

The situation highlights the need for robust cybersecurity measures in the hospitality sector. Hotels and their guests must prioritize security practices, such as enabling two-factor authentication and regularly updating passwords. Additionally, educating staff about recognizing phishing attempts can help mitigate risks.

As the ClickFix campaign continues to evolve, staying informed about the latest cybersecurity threats is essential for both businesses and individuals.

You May Also Like

Top Stories

URGENT UPDATE: The family of 15-year-old Thom Hosking has issued a heartfelt tribute following his tragic death in a crash in Bendigo on October...

Sports

Fans of English football were treated to a compelling analysis of crucial refereeing decisions during two marquee matches on October 21, 2023. In a...

Top Stories

BREAKING NEWS: Global discount retailer Costco is set to revolutionize shopping in Perth as it announces plans to open its first store in the...

Sports

Mason Cox, a beloved figure at the Collingwood Football Club, has announced he will not be offered a new contract for the upcoming season....

Top Stories

UPDATE: The mother of allegedly murdered teen Pheobe Bishop has reached out with a poignant letter to the family of Gus, a four-year-old who...

Entertainment

During the recent auctions for The Block, two teams faced disappointment as they walked away without any sales, raising questions about the future of...

Sports

Jake Connor, the Super League Man of Steel, has not been selected for the England squad ahead of the Rugby League Ashes series against...

Sports

The Melbourne Storm will not pressure coach Craig Bellamy to make a decision regarding his future beyond 2026, despite overtures from the Gold Coast...

Lifestyle

Queensland is preparing for severe thunderstorms and a heatwave today, with the Bureau of Meteorology (BOM) forecasting strong winds and large hailstones across significant...

Entertainment

The much-anticipated auction day for contestants of The Block has arrived, culminating a season filled with hard work and emotional highs and lows. This...

Entertainment

Lady Annabel Goldsmith, a prominent British socialite and philanthropist, has died at the age of 91. Her passing leaves behind a legacy marked by...

Politics

Recent allegations have surfaced regarding a toxic work culture at Westpac Rescue, a prominent emergency service organization in Australia. Reports indicate that staff members...

Copyright © All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site.