Victims risk AsyncRAT infection after being redirected to fake Booking.com sites

June 3, 2025, 9:16 p.m.

Description

Cybercriminals have launched a campaign redirecting users from gaming sites and social media to fake Booking.com websites. The scam uses fake CAPTCHA prompts to trick visitors into executing malicious commands on their devices. If successful, the attack downloads and installs AsyncRAT, a backdoor Trojan that allows remote monitoring and control of infected computers. The campaign, which began in mid-May, frequently changes its final redirect destination. The malicious actors exploit the fact that 40% of people book travel through online searches, creating ample opportunities for deception. To stay safe, users are advised to be cautious of website instructions, use anti-malware solutions, employ browser extensions that block malicious domains, and consider disabling JavaScript on unknown websites.

Date

  • Created: June 3, 2025, 7:16 p.m.
  • Published: June 3, 2025, 7:16 p.m.
  • Modified: June 3, 2025, 9:16 p.m.

Indicators

  • badgustrewivers.com.com
  • rewiewwselect.com
  • rewiewqproperty.com
  • property-paids.com
  • patheer-moreinfo.com
  • partnervrft.com
  • kvhandelregis.com
  • hekpaharma.com
  • gustescharge.com
  • guestsalerts.com
  • guestalerthelp.com
  • extranet-listing.com
  • chargesguestescenter.com
  • bkngnet.com

Attack Patterns

Additional Informations

  • Hospitality