Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware
Cybersecurity experts have highlighted a large-scale phishing operation aimed at the hospitality sector, which entices hotel managers to ClickFix-like pages and collects their login information through the use of malware such as PureRAT.
Sekoia stated, "The assailant's method of operation involved leveraging a hacked email account to dispatch harmful communications to various hotel businesses. This campaign makes use of spear-phishing emails masquerading as Booking.com to direct victims to harmful websites, utilizing the ClickFix social engineering tactic to launch PureRAT.
The campaign aims to pilfer credentials from compromised systems that provide threat actors with illicit access to booking services such as Booking.com or Expedia. These credentials are either traded on cybercrim...


