Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
phishing-campaign-intelligencecredential-stealer-activityremote-access-implantcybercrime-service-ecosystem

PureRAT Malware Campaign Targets Hotels and Guests via ClickFix Phishing

Updated 3mo agoFirst seen Nov 7, 20255 sources

A sophisticated cybercrime operation has targeted the hospitality sector by compromising hotel systems through phishing emails that impersonate Booking.com communications. Attackers use the ClickFix social engineering technique to trick hotel staff into clicking malicious links or copying and pasting PowerShell commands, which results in the installation of PureRAT malware. Once installed, PureRAT provides attackers with full remote access to hotel systems, enabling them to steal professional login credentials for booking platforms and access sensitive guest reservation data. The campaign, active since April 2025, leverages both direct email phishing and drive-by downloads to infect hotel staff, with compromised hotel account access often sold on underground forums.

With access to genuine hotel Booking.com accounts, the attackers launch highly convincing phishing attacks against travelers, using stolen reservation and contact details to increase the credibility of their messages. Victims are contacted via WhatsApp or email and directed to spoofed Booking.com pages designed to harvest banking information. The PureRAT malware, delivered via a previously unobserved loader variant using DLL sideloading and persistence mechanisms like the Run registry key, enables a wide range of malicious activities, including keylogging, webcam and microphone capture, and data exfiltration. Security researchers have highlighted the organized nature of the operation and the use of malware-as-a-service infrastructure, underscoring the ongoing threat to both hotels and their guests.

Share:
PureRAT Malware Campaign Targets Hotels and Guests via ClickFix Phishing
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Nov 7, 20258mo ago

Sekoia discloses campaign details and infrastructure findings

By November 2025, Sekoia publicly reported on the campaign, describing the ClickFix infection chain, the loader used to deliver PureRAT, and phishing infrastructure including at least one site hosted on a Russia-based IP in the OPTIMA LLC autonomous system. The report also highlighted criminal-market support for Booking.com-related phishing and stolen credentials.

Oct 1, 20259mo ago

Hotel-targeting phase observed through early October 2025

Researchers observed the initial hotel-focused phase of the campaign running from April 2025 through early October 2025. During this period, attackers continued compromising hospitality organizations and harvesting credentials for booking platforms.

Apr 1, 20251y ago

Compromised hotel accounts used to phish travelers with real booking data

Using access to hotel systems and booking-platform accounts, attackers launched secondary phishing against travelers through email and sometimes WhatsApp. The messages used stolen real reservation details and spoofed Booking.com or Expedia payment pages to steal banking information and support fraud.

Attackers deploy loader and PureRAT on compromised hotel systems

After hotel staff executed the malicious commands, attackers installed a previously unobserved loader variant similar to QuirkyLoader, using DLL sideloading, a Run registry key for persistence, and in-memory loading via AddInProcess32.exe to deploy PureRAT. This established access to hotel systems and accounts for follow-on abuse.

ClickFix phishing campaign begins targeting hotel staff

A phishing campaign targeting the hospitality sector was active by at least April 2025, using emails impersonating Booking.com or messages sent from compromised legitimate accounts to lure hotel managers and staff. Victims were directed to ClickFix-style pages with fake CAPTCHAs that tricked them into running PowerShell commands.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Affected products
3 linked
WindowsWhatsappPowershell
Organizations
11 linked
ExpediaSekoiaBooking.comMicrosoft CorporationMalwarebytesAirbnbPush SecurityAppleLolzteamAgodaOPTIMA LLC
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

PureRAT Malware Campaign Targets Hotels and Guests via ClickFix Phishing | Mallory