HomeSecurityNew phishing campaign targets hotel customers

New phishing campaign targets hotel customers

Russian hackers are reportedly behind an ongoing phishing campaign, having registered more than 4,300 domain names since the beginning of the year.

phishing hotel customers

The activity, according to NetcraftAndrew Brandt security researcher , is designed to target hospitality industry customers , specifically hotel guests who may have made travel reservations via spam emails . The campaign is said to have begun around February 2025.

Of the 4,344 domains linked to the attack, 685 contain the name “Booking,” followed by 18 with “Expedia,” 13 with “Agoda,” and 12 with “Airbnb.” These names indicate an attempt to target all popular booking and rental platforms.

See also: Police target Rhadamanthys, VenomRAT & Elysium malware – Arrests also made in Greece

“The ongoing campaign uses a sophisticated phishing kit that customizes the page presented to the website visitor, depending on a unique string in the URL path, when the target first visits the website,” Brandt said. “The customizations use the logos of major brands in the online travel industry, including Airbnb and Booking.com.”

New phishing campaign targets hotel customers

Russian hackers target hotel customers: How does the attack work?

The attack begins with a phishing email that prompts recipients to click on a link to confirm their reservation within the next 24 hours, using a credit card. If they fall for the trap, victims are taken to a fake website after initiating a chain of redirects. These fake websites follow consistent naming patterns for their domains, including phrases such as confirm, reservation, guest check, card verification, or reservation (to give them the illusion of legitimacy).

See also: How attackers turn SVG files into phishing bait

The pages support 43 different languages, allowing threat actors to target users from different regions. The page then instructs the victim to pay a deposit for their hotel reservation by entering their card information. If a user attempts to access the page directly without a unique identifier called AD_CODE, they are presented with a blank page. The fake websites also feature a fake CAPTCHA that mimics Cloudflare to mislead the target.

“After the initial visit, the AD_CODE value is written to a cookie, which ensures that subsequent pages present the same brand that is emulated by the website visitor as they click through the pages,” Netcraft said. This also means that changing the “AD_CODE” value in the URL produces a page that targets a different hotel on the same booking platform.

Once the card details, along with the expiration date and CVV number, the page attempts to process a transaction in the background, while a “chat support” window appears on the screen with steps to complete a supposed “3D Secure verification for your credit card.”

See also: DanaBot malware returns after 6 months

New phishing campaign targets hotel customers

Who is behind this scam?

The identity of the attackers remains unknown, but the use of Russian language for comments in the source code and debugger output either suggests their origin or is an attempt to cater to potential customers of the phishing kit, who may be looking to customize it to their needs.

The revelation comes just days after Sekoia warned of a large-scale phishing campaign targeting the hospitality industry, luring hotel managers to ClickFix-style pages and harvesting their credentials by deploying malware like PureRAT. It then approaches hotel customers via WhatsApp or emails with their booking details and invites them to click on a link.

In recent weeks, large-scale phishing campaigns have also impersonated multiple companies including Microsoft, Adobe, WeTransfer, FedEx, and DHL to steal credentials. The embedded HTML files display a fake login page while JavaScript code captures the credentials entered by the victim and sends them directly to the attackers.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS