
"A Russian-speaking threat behind an ongoing, mass phishing campaign has registered more than 4,300 domain names since the start of the year. The activity, per Netcraft security researcher Andrew Brandt, is designed to target customers of the hospitality industry, specifically hotel guests who may have travel reservations with spam emails. The campaign is said to have begun in earnest around February 2025."
"Of the 4,344 domains tied to the attack, 685 domains contain the name "Booking", followed by 18 with "Expedia," 13 with "Agoda," and 12 with "Airbnb," indicating an attempt to target all popular booking and rental platforms. These bogus sites follow consistent naming patterns for their domains, featuring phrases like confirmation, booking, guestcheck, cardverify, or reservation to give them an illusion of legitimacy. The pages support 43 different languages, allowing the threat actors to cast a wide net."
"The page then instructs the victim to pay a deposit for their hotel reservation by entering their card information. In the event that any user directly attempts to access the page without a unique identifier called AD_CODE, they are greeted with a blank page. The bogus sites also feature a fake CAPTCHA check that mimics Cloudflare to deceive the target."
A Russian-speaking threat registered 4,344 domains since the start of the year and launched a mass phishing campaign targeting hospitality customers beginning around February 2025. The domains include 685 containing "Booking", 18 with "Expedia", 13 with "Agoda", and 12 with "Airbnb", aiming at major booking and rental platforms. Phishing emails urge recipients to confirm bookings within 24 hours and direct victims through redirects to fake sites that use brand logos and consistent names like confirmation, booking, guestcheck, cardverify, or reservation. Pages support 43 languages, present fake Cloudflare-like CAPTCHA, and request deposit card details while requiring an AD_CODE cookie to display content.
Read at The Hacker News
Unable to calculate read time
Collection
[
|
...
]