Fake Booking.com Emails Used to Deliver DCRat Malware to Hospitality Staff
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Suspected Russian attackers are conducting a malware delivery campaign targeting the hospitality sector, particularly European organizations, by sending phishing emails that impersonate Booking.com. These emails contain fake reservation cancellation alerts that direct victims to a cloned Booking.com site. Once on the site, users encounter a fake Blue Screen of Death (BSOD) that prompts them to execute a malicious PowerShell command.
This command opens a decoy Booking.com admin page and secretly downloads a malicious project file, which is then executed using Windows’ Microsoft Build Engine (MSBuild.exe). The malware, known as DCRat, is designed to log keystrokes, drop additional payloads, and maintain persistent remote access to infected computers.
The attackers have adapted their methods from previous campaigns that relied on HTML Application files and mshta.exe to execute malicious payloads. The shift to using MSBuild represents a strategic pivot towards more evasive techniques that can bypass traditional security measures.
Organizations are advised to educate employees about the ClickFix tactic, monitor MSBuild.exe for unusual behavior, and enable PowerShell logging to detect potential threats. The use of social engineering tactics in this campaign highlights the importance of vigilance in recognizing phishing attempts.
Understanding the Risks
This incident underscores the evolving nature of cyber threats, particularly in the hospitality sector, where employees may be less familiar with cybersecurity protocols. The use of familiar brands like Booking.com in phishing attacks increases the likelihood of user engagement, making it essential for organizations to implement robust training and awareness programs.
Monitoring for unusual behavior in legitimate system binaries and the creation of suspicious files can help organizations detect and mitigate these types of attacks. The DCRat malware’s capabilities, including keystroke logging and remote access, pose significant risks to sensitive information and operational integrity.
- Fake Booking.com emails: Attackers impersonate Booking.com to deliver malware through phishing emails.
- Fake BSOD: Victims are shown a fake Windows BSOD to trick them into executing malicious commands.
- DCRat: A malware that logs keystrokes and provides remote access to infected systems.
- MSBuild.exe: A legitimate Windows utility exploited by attackers to execute malicious payloads.
- ClickFix tactic: A social engineering technique used to trick users into initiating malware infection chains.
Key Takeaways
- Educate employees about recognizing phishing emails and the ClickFix tactic.
- Monitor MSBuild.exe and other legitimate system binaries for unusual behavior.
- Enable PowerShell logging to detect suspicious commands and activities.
- Watch for the creation of suspicious file types in %ProgramData% and Internet Shortcut files in the Startup folder.
- Implement regular cybersecurity training to raise awareness of evolving threats.
Key Terms & Concepts
- DCRat: In this article, DCRat refers to malware that can log keystrokes and provide remote access to infected computers.
- PowerShell: PowerShell is a task automation framework from Microsoft that includes a command-line shell and scripting language.
- MSBuild: MSBuild is a build platform for managing the build process of .NET applications.
- ClickFix tactic: The ClickFix tactic is a social engineering method used to trick users into executing malware infection chains.
- Blue Screen of Death (BSOD): The Blue Screen of Death is an error screen displayed by Windows operating systems upon encountering a critical system error.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.