A sophisticated cybercrime operation has targeted the hospitality sector by compromising hotel systems through phishing emails that impersonate Booking.com communications. Attackers use the ClickFix social engineering technique to trick hotel staff into clicking malicious links or copying and pasting PowerShell commands, which results in the installation of PureRAT malware. Once installed, PureRAT provides attackers with full remote access to hotel systems, enabling them to steal professional login credentials for booking platforms and access sensitive guest reservation data. The campaign, active since April 2025, leverages both direct email phishing and drive-by downloads to infect hotel staff, with compromised hotel account access often sold on underground forums.
With access to genuine hotel Booking.com accounts, the attackers launch highly convincing phishing attacks against travelers, using stolen reservation and contact details to increase the credibility of their messages. Victims are contacted via WhatsApp or email and directed to spoofed Booking.com pages designed to harvest banking information. The PureRAT malware, delivered via a previously unobserved loader variant using DLL sideloading and persistence mechanisms like the Run registry key, enables a wide range of malicious activities, including keylogging, webcam and microphone capture, and data exfiltration. Security researchers have highlighted the organized nature of the operation and the use of malware-as-a-service infrastructure, underscoring the ongoing threat to both hotels and their guests.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By November 2025, Sekoia publicly reported on the campaign, describing the ClickFix infection chain, the loader used to deliver PureRAT, and phishing infrastructure including at least one site hosted on a Russia-based IP in the OPTIMA LLC autonomous system. The report also highlighted criminal-market support for Booking.com-related phishing and stolen credentials.
Researchers observed the initial hotel-focused phase of the campaign running from April 2025 through early October 2025. During this period, attackers continued compromising hospitality organizations and harvesting credentials for booking platforms.
Using access to hotel systems and booking-platform accounts, attackers launched secondary phishing against travelers through email and sometimes WhatsApp. The messages used stolen real reservation details and spoofed Booking.com or Expedia payment pages to steal banking information and support fraud.
After hotel staff executed the malicious commands, attackers installed a previously unobserved loader variant similar to QuirkyLoader, using DLL sideloading, a Run registry key for persistence, and in-memory loading via AddInProcess32.exe to deploy PureRAT. This established access to hotel systems and accounts for follow-on abuse.
A phishing campaign targeting the hospitality sector was active by at least April 2025, using emails impersonating Booking.com or messages sent from compromised legitimate accounts to lure hotel managers and staff. Victims were directed to ClickFix-style pages with fake CAPTCHAs that tricked them into running PowerShell commands.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourcehackread.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.