Categories: News

New convincing phishing campaign targets Booking.com and Blockchain.com customers

A new series of convincing phishing emails analyzed by Security Report are designed to impersonate Booking.com, but go a step further.

These emails titled “Action needed: You have Virtual Credit Cards to refund.” appear to be originating from Booking.com, with their ‘From’ email address forged to state noreply@booking.com.

To make it seem more convincing, the Reply-To is set to info@levadiahotel.gr which is the contact email of a real property, Levadia Hotel, Greece.

While spoofing the ‘Envelope From’ or ‘Mail From‘ address field is hardly new, and a commonly seen phishing tactic, the wording of the message lends some credibility to its contents.

The phishing message urges the “partner,” supposedly a property owner using Booking.com to rent their hotel or apartment, to “refund the Virtual Credit Cards associated with each reservation below.”

The phishing link at least leads to a pretty simplistic form hosted on Fleek.co’s infrastructure.

An example phishing page (archived) found linked within such emails is shown below:

Interestingly, Google Calendar app may automatically pick spammy emails arriving in your Gmail and add these to your calendar, unless your calendar settings are set appropriately to prevent this.

An identical phishing message emerged, this time appearing to originate from ‘Blockchain.com’ and once again using a spoofed ‘From’ email field.

The ‘Update your security settings’ button once again leads to a simplistic phishing form, also hosted on Fleek.co’s server, collecting your credentials.

Security Report notified fleek.co of these emails and the suspicious links prior to publishing.

These phishing messages surface at a time when threat actors are targeting Twitter users with the introduction of the platform’s new $8 fee for the “Twitter Blue” experience and verification.

In other instances, convincing phishing scams have led to major compromises including that of Dropbox’s 130 GitHub repositories after a successful phishing attack that targeted Dropbox employees.

As always, users should remain careful when it comes to clicking links or attachments in emails that appear even slightly suspicious.

Ax Sharma

Ax Sharma is an Indian-origin British security researcher, journalist and TV subject matter expert with a focus on malware analysis and cybercrime investigations. His areas of interest include open source software security, threat intel analysis, and reverse engineering. Frequently featured by leading media outlets like the BBC, Channel 5, Fortune, WIRED, The Register, among others, Ax is an active community member of the OWASP Foundation and the British Association of Journalists (BAJ).

Recent Posts

Sea Turtle Cyber Espionage Campaign Targets Telecommunication and IT Companies in the Netherlands

Telecommunication, media, internet service providers (ISPs), information technology (IT)-service providers, and Kurdish websites in the…

12 months ago

Rogue WordPress plugin: Threat hunters uncover credit card skimming campaign targeting e-commerce sites

Rogue WordPress Plugin Found to Steal Credit Card Information in Magecart Campaign Threat hunters have…

12 months ago

Albanian Parliament and telco ‘One Albania’ suffer cyber attacks

The Assembly of the Republic of Albania and telecom company One Albania have recently fallen…

12 months ago

Carbanak Banking Malware Resurfaces with Updated Tactics in Ransomware Attacks

The banking malware Carbanak has resurfaced with updated tactics, incorporating attack vendors and techniques to…

12 months ago

Theme park giant Parques Reunidos hit by a ransomware cyber attack

One of the world's largest theme park operators, Parques Reunidos has disclosed a cybersecurity incident.…

2 years ago

Phishing kit screenshots your email domain on the fly to appear real

Phishing kit used by multiple hacked sites generates a log in page on the fly…

2 years ago

This website uses cookies.