Cybersecurity alert: phishing campaigns increasingly target hotel staff | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Researchers from the cybersecurity company Bitdefender have detected two phishing campaigns targeting both hotels and other types of tourist accommodations, where instead of trying to scam travelers, the establishments themselves are attacked.

This finding means that threats focused on the hotel sector have changed course. In the past, scams on WhatsApp impersonating hotels to deceive guests had already been documented.

Now, these new actions focus on hotel staff, using as bait the usual content of the reservation inbox: problems, cancellations, invoice requests, questions about special needs, or requests for accessibility measures for the elderly.

Identity theft

In the first campaign identified in this investigation, the identity of a customer is impersonated, claiming to be unable to complete an online reservation. The message includes a link that directs hotel staff to a malicious website under the pretext of reviewing payment or identity documents of the customer.

The second impersonates Booking.com notifications to deceive hotel employees into executing a malicious command on their own systems. More specifically, the communication received at the hotel contains a link that accesses a falsified Booking.com verification page and a fake Captcha instructing staff to press Windows + R, paste the content, and press Enter, executing a PowerShell command that downloads malware. This technique, used for distributing data-stealing programs and trojans, is known as ClickFix.

Staff, in the crosshairs

Bitdefender experts argue that the significance of the Booking.com campaign lies in the fact that no software vulnerability is exploited, but rather the hotel employee is made to execute the malware. In this way, the weak point is the staff, not the software, which means that applying patches does not solve the problem.

These attacks have primarily targeted hotels in Switzerland, the United Kingdom, Vietnam, Italy, Ireland, and the United States. At this time, the authorship of neither of these two campaigns has been confirmed.

Researchers from the cybersecurity company Bitdefender have detected two phishing campaigns targeting both hotels and other types of tourist accommodations, where instead of trying to scam travelers, the establishments themselves are attacked.

This finding means that threats focused on the hotel sector have changed course. In the past, scams on WhatsApp impersonating hotels to deceive guests had already been documented.

Now, these new actions focus on hotel staff, using as bait the usual content of the reservation inbox: problems, cancellations, invoice requests, questions about special needs, or requests for accessibility measures for the elderly.

Identity theft

In the first campaign identified in this investigation, the identity of a customer is impersonated, claiming to be unable to complete an online reservation. The message includes a link that directs hotel staff to a malicious website under the pretext of reviewing payment or identity documents of the customer.

The second impersonates Booking.com notifications to deceive hotel employees into executing a malicious command on their own systems. More specifically, the communication received at the hotel contains a link that accesses a falsified Booking.com verification page and a fake Captcha instructing staff to press Windows + R, paste the content, and press Enter, executing a PowerShell command that downloads malware. This technique, used for distributing data-stealing programs and trojans, is known as ClickFix.

Staff, in the crosshairs

Bitdefender experts argue that the significance of the Booking.com campaign lies in the fact that no software vulnerability is exploited, but rather the hotel employee is made to execute the malware. In this way, the weak point is the staff, not the software, which means that applying patches does not solve the problem.

These attacks have primarily targeted hotels in Switzerland, the United Kingdom, Vietnam, Italy, Ireland, and the United States. At this time, the authorship of neither of these two campaigns has been confirmed.


——————————————————-


Click Here For The Original Source.