ECONOMY & WORK
MONEY 101
NEWS
PERSONAL FINANCE
NET WORTH
About Us Contact Us Privacy Policy Terms of Use DMCA Opt-out of personalized ads
© Copyright 2023 Market Realist. Market Realist is a registered trademark. All Rights Reserved. People may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.
MARKETREALIST.COM / NEWS

Beware of This new Scam That is Targeting Travelers Through Online Booking Sites

Utilize reputable security software and cloud services to protect devices from potential threats and phishing attempts.
PUBLISHED FEB 11, 2024
Cover Image Source: Cyber Fraud | Pexels
Cover Image Source: Cyber Fraud | Pexels

Despite widespread awareness, phishing remains one of the most persistent and effective attack vectors in the world of cyber threats. From scammers posing as reputable banks to text messages mimicking delivery notifications, and even malicious code hidden within seemingly innocuous images, phishing attacks can target anyone with access to digital devices. One scam recently identified by cybersecurity professionals is the utilization of sophisticated infostealers, specifically targeting the hospitality industry through online booking services. 

A smart phone with the travel app Booking.com is seen on the screen in Hong Kong | Getty Images | Photo by S3studio
Image Source: Getty Images | Photo by S3studio

As part of this scam, a fraudster initiates a booking request, opting for the "pay at hotel" option, and proceeds to spam the hotel with a series of urgent and seemingly authentic emails containing links to supposed "photos." However, these links actually lead to the execution of an infostealer, compromising the hotel's security.

While initially aimed at hotels, this nefarious phishing campaign has evolved into a multi-stage attack, subsequently targeting customers of these booking platforms. The attack is carried out in three primary steps, which are executing the infostealer, contacting the victim, and ultimately trapping the victim with a link.

A 12-year-old boy looks at a iPad screen on October 27, 2023 in Swansea, Wales. Getty Images | Photo by Matt Cardy
Image Source: Getty Images | Photo by Matt Cardy

After infiltrating the hotel's system, the attacker first gains access to legitimate customer communications. Typically, users are advised to rely on official communication channels provided by the booking platform to avoid fraudulent interactions. However, with the attacker now able to exploit these trusted channels, such precautions become ineffective.

The attacker proceeds to send personalized messages to intended victims, leveraging typical phishing strategies such as urgency, fear, and the need for immediate action. Crafted to mimic authentic hotel communications, these messages instill a false sense of trust in recipients, further facilitating the success of the phishing scheme. On top of that, the messages are disseminated through the booking platform's messaging system, adding a sense of legitimacy that would otherwise be absent in traditional email-based phishing attempts.

Image Source: Pexels|Photo by Alex Green
Image Source: Pexels | Photo by Alex Green

The victim then receives a message containing a deceptive link, purportedly for additional card verification to prevent the cancellation of their booking. Fearing the loss of their reservation, the victim complies with the instructions outlined in the message and clicks the link. This action triggers the execution of a script encoded within a JavaScript Base64 script, which is downloaded onto the victim's device.

The downloaded script is designed to evade detection by security analysts, utilizing various methods to gather information about the victim's browser environment, including browser capabilities and attributes. This data is then compiled into a data object and appears to be transmitted to a server via a POST request.

Following the successful execution of the script, the victim is directed to a phishing site posing as a legitimate payment page, where they are prompted to enter their credit card information. To further enhance the credibility of the scam, the attacker implements a smart-chat support channel.

A logo of Booking.com is pictured on a computer screen | Getty Images | Photo by Yuriko Nakao
Image Source: Getty Images | Photo by Yuriko Nakao

Several red flags indicate the fraudulent nature of the message, including urgent language warning of reservation cancellation, a suspicious URL that does not match the official website domain, and the presence of threatening language. To mitigate the risk of falling victim to such phishing attacks, individuals are advised to exercise caution and remain vigilant.

MORE ON MARKET REALIST
While he has a spotless track record on screen, Jennings loves to have fun behind the scenes.
10 hours ago
The contestant, Desiree Kramer pulled off a stunning sub-two second win in the finale.
11 hours ago
The painting from former NFL Player Ernie Barnes turned out to be one of the most valuable pieces.
12 hours ago
Contestant Eleni Kapetanakis faced a rather unusual 'Place' category puzzle on the show.
13 hours ago
The seller brought the original tie and handkerchiefs worn by James Gandolfini on 'The Sopranos.'
1 day ago
Fans said they weren't 'having a few laughs' after Kiana Moreland missed the $100,000 jackpot.
1 day ago
'I had no idea it existed,' one viewer said after contestant Auriel Heath failed to guess the rare dish.
1 day ago
Though Banana Phone didn’t land a deal on the show, it gained massive traction afterward.
2 days ago
Ken Jennings recently won $1 million on 'Who Wants to Be a Millionaire,' and says he could do it again.
2 days ago
Genius Litter founder Ramon Van Meer impressed the panel and ended up triggering a Shark fight.
3 days ago
Contestants Danielle Williams and Adam Bencan took the loss in stride, but viewers were enraged.
3 days ago
Ken Jennings explained what he does differently compared to the show's former legendary host, Alex Trebek.
3 days ago
Contestant Elizabeth Caprini could've won a brand new Mercedes-Benz, but was stumped by a simple puzzle.
4 days ago
The father-son duo of Miles and Maurice Huffman shared their struggles ahead of negotiations.
4 days ago
While the item was potentially worth $20,000, Harrison admitted he couldn't sell it.
4 days ago
The co-founders of Nutr blew the only chance they had to convince Daniel Lubetzky.
4 days ago
The player, Brandon Rothstein had cracked the puzzle even before the timer kicked off.
5 days ago
Stars from the Real Housewives Franchise, Kandi Burrus-Tucker and Kyle Richards, cracked the host up
5 days ago
Emmitt Smith was happy to authenticate his signature on a photo from his first NFC Championship game.
5 days ago
Melissa Brickey seemed to be caught up in a loop of losing her winnings — until she finally escaped her unlucky streak.
6 days ago