started · updated
Cybercriminals target hotels with fake Windows Blue Screens
Cybercriminals are employing a new phishing technique known as ‘ClickFix’ that specifically targets the hotel and hospitality industry in Europe. The attack begins with a phishing email disguised as a booking cancellation from Booking.com.
When employees click the link in the email, they are directed to a fraudulent website that mimics the official platform. The site then triggers a fake Windows Blue Screen of Death (BSOD) in full-screen mode. To resolve the perceived system error, the fake screen instructs users to open the Windows ‘Run’ dialog, press a specific key combination, and paste a command.
Executing these steps installs malware that allows attackers to access hotel networks, steal sensitive data, and compromise internal IT infrastructures. The method was identified by malware analyst JAMESWT_.