The hackers pose as Booking.com to deploy malware for fraud and theft
Microsoft recently warned of an ongoing phishing campaign by threat actor Storm-1865, which targets hospitality organizations across North America, Europe, Oceania, and South and Southeast Asia by impersonating Booking.com and using the ClickFix technique to deliver credential-stealing malware.
Vishnu Rageev R is a journalist with more than 15 years of experience in business journalism. Before joining Asian Media Group in 2022, he worked with BW Businessworld, IMAGES Group, exchange4media Group, DC Books, and Dhanam Publications in India. His coverage includes industry analysis, market trends and corporate developments, focusing on retail, real estate and hospitality. As a senior journalist with Asian Hospitality, he covers the U.S. hospitality industry. He is from Kerala, a state in South India.
Microsoft Warns Hotels: Protect Against Booking.com Phishing Scam
MICROSOFT RECENTLY WARNED of a phishing campaign targeting the hospitality sector, where attackers impersonate Booking.com and use the ClickFix social engineering technique to deliver credential-stealing malware. The tech giant tracks the threat actor, Storm-1865, which has targeted hospitality organizations across North America, Europe, Oceania, and South and Southeast Asia in an ongoing campaign.
The hackers deploy info-stealing malware for financial fraud and theft through fake emails impersonating the agency, Microsoft said in a blog post.
“Starting in December, leading up to some of the busiest travel days, Microsoft Threat Intelligence identified a phishing campaign that impersonates online travel agency Booking.com and targets organizations in the hospitality industry,” Microsoft said. “The campaign uses ClickFix to deliver multiple credential-stealing malware strains to facilitate financial fraud and theft. As of February, the campaign is ongoing.”
Microsoft said the attack specifically targets individuals in hospitality organizations in North America, Oceania, South and Southeast Asia, and Europe who are likely to work with Booking.com.
“The phishing emails claim to be from Booking.com and reference negative reviews, account verification, promotions, or guest requests,” the blog post stated. “They include links or PDFs leading to fake Booking.com sites that use ClickFix to trick users into downloading malware. ClickFix displays an error or verification prompt, instructing users to copy an unseen string, paste it into a Windows terminal, and execute it.”
“Unfortunately, phishing attacks by criminal organizations pose a significant threat to many industries,” Booking.com said, according to SecurityWeek. “While Booking.com’s systems have not been breached, we are aware that some accommodation partners and customers have been impacted by phishing attacks from professional criminals attempting to take over their local computer systems with malware.”
Microsoft noted that Storm-1865 has been active since 2023, targeting hotel guests and e-commerce users with phishing campaigns.
“The number of accommodations affected by this scam is a small fraction of those on our platform, and we continue to make significant investments to limit the impact on our customers and partners,” Booking.com said.
In Storm-1865 attacks observed by Microsoft, victims are prompted to check a box to prove they are human and then press Windows + R, Ctrl + V, and Enter. “Checking the box copies a command to the clipboard, and the key presses open the Windows Run window, paste the command, and execute it,” Microsoft Threat Intelligence found. “The command downloads and runs malware such as XWorm, Lumma, VenomRAT, AsyncRAT, Danabot or NetSupport RA.”
“All these payloads include capabilities to steal financial data and credentials for fraudulent use, which is a hallmark of Storm-1865 activity,” Microsoft said. “The addition of ClickFix to this threat actor’s tactics, techniques, and procedures shows how Storm-1865 is evolving its attack chains to bypass conventional security measures.”
Meanwhile, Booking.com said it is committed to helping partners and customers stay protected.
“We provide ongoing cybersecurity education and resources to our partners to enhance their defenses against such threats,” Booking.com told SecurityWeek.
In 2022, InterContinental Hotels Group franchisees sued the company over a cyberattack that disrupted booking channels, alleging IHG ignored prior breach warnings. The attack affected reservations, customer care centers, and internal systems, including Merlin and the Help Desk.
Nightfood Holdings plans to acquire two hotels in California worth $80M.
Hotels will feature AI-powered service robots.
The strategy combines automation revenue with real estate growth.
NIGHTFOOD HOLDINGS PLANS to acquire two hotels in California to test the use of AI-driven robots in guest services. The company also announced plans for a broader tech-integrated portfolio.
The company has signed a letter of intent to acquire a 155-room Holiday Inn in Victorville, California, for approximately $27 million, with plans to convert it into a Courtyard by Marriott. A second deal is underway for a Hilton Garden Inn in Rancho Mirage, valued around $24.5 million. The two properties represent an estimated $80 million in assets.
Both Victorville and Rancho Mirage properties will serve as operational testbeds for automation and future revenue optimization. The Rancho Mirage hotel sits adjacent to Disney’s upcoming Cotino resort project.
Nightfood Holdings combines hotel ownership with Robotics-as-a-Service through its Skytech subsidiary. The company plans to deploy guest-facing robots for food delivery, laundry transport and concierge functions, along with back-end automation for cleaning and operations. Robots will be integrated into its own properties and eventually licensed to third-party hotel operators.
"We're pairing recurring RaaS income with long-term real estate value creation," the company stated. "These flagship hotels will serve as model environments for automation deployment and performance tracking."
Nightfood has also partnered with Bear Robotics to expand its automation capabilities across the portfolio.
The strategy targets cost reduction, operational efficiency and enhanced guest experience. Industry reports project 30 to 40 percent cost savings from hotel automation, with AI in hospitality expected to grow to $1.46 billion by 2029. The global hospitality robotics market is forecasted to reach $107 billion by 2034.
Recently, Vision Hospitality Group deployed its AI-driven procure-to-pay platform across more than 40 properties, aiming to automate accounts payable processes.
By clicking the 'Subscribe’, you agree to receive our newsletter, marketing communications and industry
partners/sponsors sharing promotional product information via email and print communication from Asian Media
Group USA Inc. and subsidiaries. You have the right to withdraw your consent at any time by clicking the
unsubscribe link in our emails. We will use your email address to personalize our communications and send you
relevant offers. Your data will be stored up to 30 days after unsubscribing.
Contact us at data@amg.biz to see how we manage and store your data.