PureRAT ClickFix malware delivery chain targeting hotel systems
Malware Activity
Summary
Hide ▲
Show ▼
A PureRAT infection chain is actively targeting hotel systems, enabling credential theft, remote access, and command execution. The malware is delivered through ClickFix pages reached via spear-phishing emails that impersonate Booking.com. The infection flow uses PowerShell, a downloaded ZIP archive, and DLL side-loading to establish persistence. The activity has been observed since at least April 2025 and remained operational in early October 2025.
Related Happenings
Hotel and hospitality photo-ZIP phishing campaign
Campaign
H score40
First: 26.06.2026 12:27
Last: 26.06.2026 12:27
Sources 1
About this happening:
An active phishing campaign is targeting hotel and hospitality organizations across Europe and Asia, increasing the risk of front-desk machine compromise and durab...
Hotel and hospitality photo-ZIP phishing campaign
CampaignAbout this happening: An active phishing campaign is targeting hotel and hospitality organizations across Europe and Asia, increasing the risk of front-desk machine compromise and durab...
ScarCruft NarwhalRAT spear-phishing malware activity
Malware Activity
H score23
First: 16.06.2026 11:14
Last: 16.06.2026 11:14
Sources 1
About this happening:
ScarCruft (APT37) is using spear-phishing emails that impersonate Microsoft Account security alerts to deliver NarwhalRAT, creating a multi-stage malware threa...
ScarCruft NarwhalRAT spear-phishing malware activity
Malware ActivityAbout this happening: ScarCruft (APT37) is using spear-phishing emails that impersonate Microsoft Account security alerts to deliver NarwhalRAT, creating a multi-stage malware threa...
Formbook phishing campaign using DLL sideloading and obfuscated JavaScript
Campaign
H score30
First: 20.04.2026 18:01
Last: 20.04.2026 18:01
Sources 1
About this happening:
The Formbook phishing operation is targeting Windows organizations across Greece, Spain, Slovenia, Bosnia, Croatia and South America, using DLL sideloading and...
Formbook phishing campaign using DLL sideloading and obfuscated JavaScript
CampaignAbout this happening: The Formbook phishing operation is targeting Windows organizations across Greece, Spain, Slovenia, Bosnia, Croatia and South America, using DLL sideloading and...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware Activity
H score29
First: 01.04.2026 16:30
Last: 01.04.2026 16:30
Sources 1
About this happening:
The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Venom Stealer MaaS continuous credential theft and exfiltration
Malware ActivityAbout this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...
Torg Grabber browser-extension theft activity
Malware Activity
H score36
First: 25.03.2026 20:32
Last: 25.03.2026 20:32
Sources 1
About this happening:
The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...
Torg Grabber browser-extension theft activity
Malware ActivityAbout this happening: The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...
Timeline
-
10.11.2025 11:11 2 articles · 8mo ago
Sekoia discloses Booking.com impersonation campaign deploying PureRAT against hotels
Initial DisclosureSekoia described a massive phishing campaign against hotel establishments that impersonates Booking.com, sends malicious messages from compromised email accounts, and lures staff to ClickFix pages with a fake reCAPTCHA flow. Victims are prompted to copy and run a malicious PowerShell command that downloads a ZIP archive, loads PureRAT (aka zgRAT) through DLL side-loading, and establishes persistence with a Run registry key, enabling credential theft, remote access, data exfiltration, and fraudulent access to booking platforms such as Booking.com and Expedia. Sekoia assessed the activity as active since at least April 2025 and operational as of early October 2025.
Show sources
- Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware — thehackernews.com — 10.11.2025 11:11
- Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware — thehackernews.com — 10.11.2025 11:11