0x666 - Teknik - Phishing Campaigns “I Paid Twice” Targeting Booking com Hotels and Customers

0x666 - Teknik - Phishing Campaigns “I Paid Twice” Targeting Booking com Hotels and Customers

🎙 PolySécure Podcast 👥 540 📅 November 20, 2025 ⏱ 28 min 👁 30 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

phishingcybercrimeClickFixPureRATBooking.com

Summary

In this technical podcast episode, Jérémy Scion and Quentin Bourgue, analysts at Sekoia, discuss a sophisticated phishing campaign dubbed ‘Double Paiement’ targeting hotels and their customers on booking platforms like Booking.com, Expedia, and Airbnb. The attack operates in two phases: first, hotels are compromised through phishing emails that mimic Booking.com, using the ClickFix technique to trick hotel staff into executing a PowerShell command that loads PureRAT malware via DLL side-loading. This grants attackers access to hotel management accounts, allowing them to steal reservation details. In the second phase, these stolen credentials are sold on cybercriminal forums, and buyers contact customers via email or WhatsApp, impersonating the hotel to request ‘bank verification.’ Victims are redirected to fake Booking.com pages that initiate unauthorized transactions. The analysts highlight the professionalization of cybercrime, with a clear division of labor among malware developers, access brokers, and fraudsters, primarily from the Russian-speaking ecosystem. They also discuss the evolution from artisanal operations to multiple professional clusters and the use of automated detection methods based on domain names and IPs. The episode concludes with a mention of sharing indicators of compromise with the community.

186 words

Critical Evaluation

Value of the Information & Strength of the Argument

The podcast provides valuable insights into a real-world cybercrime campaign, detailing the technical methods and the business model behind it. The argumentation is solid, based on the analysts’ direct investigation and experience. They explain the ClickFix technique, the use of PureRAT as malware-as-a-service, and the division of labor in the cybercriminal ecosystem. The discussion is coherent and well-structured, with concrete examples and a clear explanation of the attack chain.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the analysts present their own research without citing external sources in the episode, but they mention that similar campaigns have been documented by Microsoft and other CTI actors. The title accurately reflects the content. The podcast is a discussion, not a formal publication, so the depth of evidence is limited. No comments were provided for analysis.

145 words

Title / Content Match

The title accurately reflects the content, which focuses on phishing campaigns targeting Booking.com hotels and customers.

Quality & Reliability

7/10

The podcast features two cybersecurity analysts from Sekoia presenting their research on a phishing campaign. They provide detailed technical insights and reference their own investigation, but the episode is a discussion rather than a formal publication, and some claims lack external verification.

Key Moments

Cited Sources

  • Sekoia Blog — The analysts mention publishing a blog post about this investigation, which likely contains detailed technical analysis and IOCs.

Concurring Sources

Contribution & Novelties

The podcast provides an in-depth look at a specific phishing campaign targeting the hospitality sector, highlighting the use of ClickFix and the professionalization of cybercrime. It offers practical insights for defenders and emphasizes the importance of monitoring such threats.

Pour aller plus loin :

  • ClickFix technique — MITRE ATT&CK technique for user execution, relevant to the social engineering aspect.
  • PureRAT malware — Malpedia entry for PureRAT, providing technical details.
  • DLL Side-Loading — MITRE ATT&CK technique for DLL side-loading, used in the infection chain.

83 words

Radar Profile

The radar profile shows high scores in information quantity and technical level, with moderate scores in quality and reliability. This indicates a content-rich episode with solid technical depth, but the reliability is limited by the lack of external citations and the informal podcast format.

Reliability 7/10