216.73.217.22

Victims risk AsyncRAT infection after being redirected to fake Booking.com sites

· Published 03/06/2025 19:16 · Modified 03/06/2025 21:16

Export JSON

Essential information

Published
03/06/2025 19:16
Modified
03/06/2025 21:16
Tags
2025-06-03 asyncrat captcha scam clipboard hijacking social engineering travel booking
Related entities
14 observables, 5 techniques (mitre), 1 malware, 1 others

Description

Cybercriminals have launched a campaign redirecting users from gaming sites and social media to fake Booking.com websites. The scam uses fake CAPTCHA prompts to trick visitors into executing malicious commands on their devices. If successful, the attack downloads and installs , a backdoor Trojan that allows remote monitoring and control of infected computers. The campaign, which began in mid-May, frequently changes its final redirect destination. The malicious actors exploit the fact that 40% of people book travel through online searches, creating ample opportunities for deception. To stay safe, users are advised to be cautious of website instructions, use anti-malware solutions, employ browser extensions that block malicious domains, and consider disabling JavaScript on unknown websites.

External references