Russian-speaking threat actors have orchestrated a large-scale phishing campaign targeting the hospitality industry by registering over 4,300 domains that impersonate well-known travel and booking platforms such as Booking.com, Expedia, Agoda, and Airbnb. The campaign, active since at least February 2025, uses spam emails to lure hotel guests into clicking on links that redirect them to sophisticated fake websites. These sites are designed to appear legitimate, supporting 43 languages and employing brand logos, fake CAPTCHA checks, and customizations based on unique URL strings to increase credibility. Victims are prompted to enter their credit card details under the guise of confirming or paying for hotel reservations, with the sites even simulating 3D Secure verification processes to further the deception.
Analysis by Netcraft and security researchers has linked the campaign to Russian threat actors, citing language artifacts in source code and debugger output. The phishing infrastructure is highly organized, with domain names following consistent patterns such as "confirmation," "booking," and "reservation" to enhance the illusion of authenticity. The campaign's scale and technical sophistication pose a significant threat to travelers and the hospitality sector, with the potential for widespread theft of payment data and personal information. Security experts recommend heightened vigilance for unsolicited travel-related emails and verification of booking communications through official channels.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Security reporting in mid-November 2025 described an ongoing Russian-linked phishing operation using roughly 4,300 spoofed travel and hotel booking websites to steal guests' payment card data. The campaign targeted travelers by impersonating legitimate accommodation and travel services.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.