A newly uncovered phishing campaign is targeting employees in the hospitality sector by impersonating Booking.com, one of the world’s largest online travel agencies. At the heart of the campaign is a clever trick called ClickFix—a social engineering tactic that convinces users to execute malware on their own systems.
First detected in December 2024, the campaign has been traced to a threat actor Microsoft tracks as Storm-1865, and its impact has stretched across North America, Europe, Oceania, and Southeast Asia. The goal? Steal login credentials, plant malware, and commit financial fraud.
A Simple Email, a Fake Review, and a Deceptive Link
Booking.com as the Bait
The attack begins with an email that appears to come from Booking.com, claiming a customer has posted a negative review. The target is asked to respond or provide feedback.
Included in the message is either a link or a PDF file with a clickable link, which appears to take the recipient to the real Booking.com website. But clicking it leads elsewhere—a fake CAPTCHA page, carefully designed to mimic Booking.com’s branding in the background.
This tactic helps lower the victim’s guard, encouraging them to follow on-screen instructions.
ClickFix: The Technique Fooling Even Cautious Users
Turning Victims into Unknowing Attackers
The ClickFix method is at the core of this phishing attack. Once users reach the fake CAPTCHA screen, they’re prompted to press Windows + R, paste a command from the site, and press Enter.
That command quietly uses a built-in Windows utility—mshta.exe—to pull in the malware payload.
This user-driven technique works so well because it bypasses traditional security filters, which often rely on detecting malicious links or file attachments. In this case, the user unwittingly runs the code themselves, making the attack difficult to stop.
What Happens Next?
The malware installed varies but includes well-known threats like:
- XWorm – A remote access trojan (RAT)
- Lumma Stealer – Steals browser data, credentials, and more
- VenomRAT, AsyncRAT, Danabot, NetSupport RAT – Other tools for stealing data and gaining remote control
All of them give the attacker ongoing access to the victim’s machine and sensitive information.
Storm-1865: A Growing and Evolving Threat Actor
From E-commerce to Hospitality
Microsoft previously observed Storm-1865 targeting online shoppers with fake payment pages linked to platforms like Gmail and iCloud. Their tactics continue to evolve as they now use vendor-specific lures, such as Booking.com-themed emails, to reach industry-specific employees.
This campaign is part of a larger trend in which threat actors are refining their phishing lures to match the roles and behaviors of their targets.
Not Just Criminals: APTs Are Now Using ClickFix Too
Nation-State Actors Adopt the Same Technique
Cybersecurity experts have reported that even advanced persistent threat (APT) groups linked to countries like Russia and Iran are now using ClickFix in their campaigns.
One example is APT28 (associated with Russia), and another is MuddyWater (believed to be linked to Iran). Both have integrated ClickFix in recent social engineering attacks.
According to Group-IB, the success of this method lies in its ability to trick users into completing the infection process themselves—a clever way to dodge detection.
Variations on the ClickFix Theme
ClickFix Is Versatile—and It’s Spreading Fast
Security firms have observed several variations of ClickFix-based attacks, including:
- Fake CAPTCHA challenges that launch PowerShell scripts delivering Lumma and Vidar Stealers
- Google reCAPTCHA-themed lures deployed by the Blind Eagle group
- Booking confirmation links that redirect to malware download pages
- Windows-themed decoy pages that prompt similar command execution steps
Each variant uses a false problem and a misleading solution to push the user into action. And once they comply, the malware silently moves in.
GitHub Repositories as Malware Launchpads
AI-Generated Pages, Real-World Damage
In one ClickFix campaign analyzed by Trend Micro, attackers uploaded fake GitHub repositories using AI-generated descriptions and fake reviews. These pages offered:
- Game cheats
- Cracked tools
- Cryptocurrency utilities
Victims downloaded ZIP files thinking they were getting something helpful, but instead received a loader program—named SmartLoader—which deployed Lumma Stealer.
The abuse of trusted platforms like GitHub makes detection and prevention much harder, especially for individuals and small businesses.
G DATA Reports Regional Focus
Victims in Germany and the Philippines
According to German security firm G DATA, one variation of this campaign has heavily targeted users in Germany and the Philippines.
The company observed fake Booking.com messages embedded with ClickFix steps that led directly to the Lumma Stealer—a repeated choice among attackers due to its wide functionality and high success rate.
Other Recent Stealer Campaigns and Evolution
Beyond Lumma: The Rise of StrelaStealer and Custom Loaders
Alongside Lumma and XWorm, other stealers are appearing more often. Trustwave recently shared findings about StrelaStealer, delivered through fake invoice emails.
This malware uses layered obfuscation and custom crypters like Stellar Loader to hide from antivirus tools. It reflects a larger move toward highly customized delivery tools built to match specific payloads.
Why ClickFix Works So Well
It Uses Trust, Not Tech, to Bypass Security
ClickFix doesn’t rely on hidden exploits or zero-day flaws. Instead, it exploits human behavior:
- Users believe they’re solving a problem
- They follow the instructions willingly
- The malware avoids detection because the user starts the process
It’s a new twist on social engineering that combines familiar-looking websites, minor tech jargon, and urgency to move quickly from click to infection.
How to Protect Against ClickFix Campaigns
Tips for Individuals and Organizations
- Never follow manual commands from unknown websites
- Watch for urgency or emotional manipulation in emails
- Train teams on emerging phishing methods, including ClickFix
- Block access to mshta.exe if not used internally
- Use email filtering to catch fake travel or invoice messages
- Apply behavioral monitoring tools to detect abnormal command use
FAQs
What is the ClickFix technique in phishing?
ClickFix is a social engineering method where a fake webpage tells the user to run a command on their computer, usually resulting in malware installation.
How is Booking.com used in the phishing scam?
Attackers pretend to send negative reviews from Booking.com to hospitality workers. The email includes links or PDFs that direct users to fake sites prompting malware installation.
What types of malware are dropped in these attacks?
Common payloads include Lumma Stealer, XWorm, NetSupport RAT, VenomRAT, and Danabot.
Why does ClickFix evade security tools?
Because the victim willingly runs the command, traditional antivirus tools may not see it as suspicious.
Who is Storm-1865?
A threat actor tracked by Microsoft responsible for phishing and financial fraud across various industries, now using ClickFix tactics.
Are APT groups using ClickFix?
Yes. Nation-state actors from countries like Russia and Iran have adopted ClickFix to deliver malware like KoSpy and SMOKESABER.

74 Comments
ZaGilLNPQLMniRlQ
DBUWcZKrPsdXysUTmhNe
Needed to find a safe link for 55clubdownload, and this page hit the spot! Easy to navigate, no ads popping up everywhere. I Recommend visiting 55clubdownload if you need the app.
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
3pattibluegame, this is where I spend my evenings playing 3 Patti. Great for killing time! Game runs smoothly and the app is pretty user-friendly. 3pattibluegame
I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.
I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.
Your point of view caught my eye and was very interesting. Thanks. I have a question for you. https://accounts.binance.info/bn/register?ref=WTOZ531Y
Thanks for sharing. I read many of your blog posts, cool, your blog is very good. https://accounts.binance.com/si-LK/register?ref=LBF8F65G
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
a45com https://www.a45com.org
pagcor https://www.ngpagcor.net
slotphlogin https://www.exslotphlogin.net
balato88 https://www.balato88u.com
tayabet https://www.yetayabet.net
phtaya01 https://www.phtaya01.org
philucky https://www.usphilucky.org
jl16login https://www.adjl16login.net
taya333 https://www.taya333.org
phtaya11 https://www.phtaya11y.com
bk8casino https://www.bk8casinovs.com
nustaronline https://www.umnustaronline.org
philbet https://www.philbetts.net
taya777login https://www.wtaya777login.com
phtaya1 https://www.phtaya1.org
pin77 app https://www.pin77.tech
phtaya06 https://www.phtaya06y.com
gkbet https://www.gkbeth.org
okebet168 https://www.okebet168u.org
tayawin https://www.tayawinch.net
vipjili https://www.vipjiliji.com
98jili https://www.98jilig.com
phwin25 https://www.phwin25g.net
tongits go https://www.yatongits-go.net
jiliokcc https://www.jiliokccw.com
peryaplus https://www.rsperyaplus.net
phtaya10 https://www.phtaya10y.com
jl10 casino https://www.jl10-casino.net
okebet3 https://www.okebet3u.org
fb777login https://www.fb777loginv.org
phtaya 63 https://www.phtaya-63.org
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
Your article helped me a lot, is there any more related content? Thanks!
Yo 3389bet is a site with lots of options, i gave it a shot, good luck all, check em out! 3389bet
Yo, 84win219! Just signed up, and the site is smooth. Deposits were quick, and the game selection is solid. Hoping for some big wins, but even if not, seems like a legit place to have some fun. Check them out here: 84win219
Pagcor Online Slots! Now this is what I’m talkin’ about! A great selection of games and the chance to win big? I’m in! Let’s spin those reels! Check it out! pagcoronlinseslots
g7win https://www.beg7win.org
252winbet? Yeah, I’m down with that! Been on a winning streak lately. You should check them out. Good vibes only. 252winbet
212betlogin, man, that login is so smooth! Get in, get bets placed, get paid! Can’t beat it. 212betlogin
918betlogin – legit and trustworthy platform. Made some decent money on there and withdrawals are easy. I recommend it! 918betlogin
jiliasia7 app|jiliasia7 slots|jiliasia7 download|jiliasia7 login|jiliasia7 casino Experience the ultimate online gaming at Jiliasia7 Casino, the top choice for players in the Philippines. Play the best jiliasia7 slots, access your secure jiliasia7 login, and get the jiliasia7 app via the official jiliasia7 download to start winning today! visit: jiliasia7
Dudes, gotta say the 667betapp is smooth! Easy to use on the go, and looks great. download if you’re mobile. Here’s the link 667betapp
The playtimeregister process was surprisingly quick. No unnecessary info needed! Ready to start the fun! Register here: playtimeregister
Ey up! Took a gamble with x777hh. Website’s pretty easy to use. Give it a whirl, who knows, you might get lucky! Click the link: x777hh
Thanks for sharing. I read many of your blog posts, cool, your blog is very good.
Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?
7vvbet, eh? Never tried it before. I’m always looking for new places to play. Hopefully, it’s not a scam! Giving it a shot. Find it here 7vvbet.
888phpcasino sounds interesting. The name alone makes me curious. I’m hoping for some good wins this time! Check it out 888phpcasino.
Downloading the a777gameapk right now. Hope the app is smooth and the games are legit. Fingers crossed for a good experience! Download yours here a777gameapk.
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me? https://accounts.binance.com/ru/register?ref=O9XES6KU
Your article helped me a lot, is there any more related content? Thanks!
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
Thanks for sharing. I read many of your blog posts, cool, your blog is very good. https://accounts.binance.com/en-ZA/register-person?ref=B4EPR6J0
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
Your article helped me a lot, is there any more related content? Thanks! https://www.binance.com/register?ref=IHJUI7TF
Your article helped me a lot, is there any more related content? Thanks! https://accounts.binance.info/lv/register-person?ref=SMUBFN5I
Your point of view caught my eye and was very interesting. Thanks. I have a question for you.
Gave sao29win a whirl last night and had a decent run. A few wins, a few losses, you know how it goes. Seems legit enough. I’ll probably be back. Head there for fun! sao29win
Just signed up for vipjili and the welcome bonus was pretty sweet. Lots of options to choose from. Gonna see if I can turn this bonus into something big! Best of luck to you too! vipjili
I stumbled across 7e77bd the other day. Clean interface and easy to use. Nothing groundbreaking, but it does the job. Worth a look-see if you’re looking for something new. Go there now! 7e77bd
Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me? https://www.binance.info/es-MX/register?ref=GJY4VW8W