{"id":58296,"date":"2025-03-13T15:00:00","date_gmt":"2025-03-13T15:00:00","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/"},"modified":"2025-03-13T15:00:00","modified_gmt":"2025-03-13T15:00:00","slug":"phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/","title":{"rendered":"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware"},"content":{"rendered":"<p>Starting in December 2024, leading up to some of the busiest travel days, Microsoft Threat Intelligence identified a phishing campaign that impersonates online travel agency Booking.com and targets organizations in the hospitality industry. The campaign uses a social engineering technique called ClickFix to deliver multiple credential-stealing malware in order to conduct financial fraud and theft. As of February 2025, this campaign is ongoing.<\/p>\n<p>This phishing attack specifically targets individuals in hospitality organizations in North America, Oceania, South and Southeast Asia, and Northern, Southern, Eastern, and Western Europe, that are most likely to work with Booking.com, sending fake emails purporting to be coming from the agency.<\/p>\n<p>In the ClickFix technique, a threat actor attempts to take advantage of human problem-solving tendencies by displaying fake error messages or prompts that instruct target users to fix issues by copying, pasting, and launching commands that eventually result in the download of malware. This need for user interaction could allow an attack to slip through conventional and automated security features. In the case of this phishing campaign, the user is prompted to use a keyboard shortcut to open a Windows Run window, then paste and launch a command that the phishing page adds to the clipboard.<\/p>\n<p>Microsoft tracks this campaign as Storm-1865, a cluster of activity related to phishing campaigns leading to payment data theft and fraudulent charges. Organizations can reduce the impact of phishing attacks by educating users on recognizing such scams. This blog includes additional recommendations to help users and defenders defend against these threats.<\/p>\n<h2 class=\"wp-block-heading\" id=\"phishing-campaign-using-the-clickfix-social-engineering-technique\">Phishing campaign using the ClickFix social engineering technique<\/h2>\n<p>In this campaign, Storm-1865 identifies target organizations in the hospitality sector and targets individuals at those organizations likely to work with Booking.com. Storm-1865 then sends a malicious email impersonating Booking.com to the targeted individual. The content of the email varies greatly, referencing negative guest reviews, requests from prospective guests, online promotion opportunities, account verification, and more.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig1-sample-phishing-email.webp\" alt=\"A screenshot of a email\" class=\"wp-image-137940 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig1-sample-phishing-email.webp\"><figcaption class=\"wp-element-caption\">Figure 1. A sample phishing email, purporting to be from a prospective guest.<\/figcaption><\/figure>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig2-sample-phishing-email.webp\" alt=\"A screenshot of a contact us\" class=\"wp-image-137941 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig2-sample-phishing-email.webp\"><figcaption class=\"wp-element-caption\">Figure 2. Another sample phishing email, purportedly requiring the recipient to address negative feedback about a hotel.<\/figcaption><\/figure>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"672\" height=\"769\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig3-sample-phishing-email.jpg\" alt=\"A screenshot of a security alert\" class=\"wp-image-137942\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig3-sample-phishing-email.jpg 672w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig3-sample-phishing-email-262x300.jpg 262w\" sizes=\"auto, (max-width: 672px) 100vw, 672px\"><figcaption class=\"wp-element-caption\">Figure 3. Another sample phishing email, purportedly requiring the recipient to verify their Booking.com account.<\/figcaption><\/figure>\n<p>The email includes a link, or a PDF attachment containing one, claiming to take recipients to Booking.com. Clicking the link leads to a webpage that displays a fake CAPTCHA overlayed on a subtly visible background designed to mimic a legitimate Booking.com page. This webpage gives the illusion that Booking.com uses additional verification checks, which might give the targeted user a false sense of security and therefore increase their chances of getting compromised.<\/p>\n<p>The fake CAPTCHA is where the webpage employs the ClickFix social engineering technique to download the malicious payload. This technique instructs the user to use a keyboard shortcut to open a Windows Run window, then paste and launch a command that the webpage adds to the clipboard:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig4-fake-booking-com-page.webp\" alt=\"A screenshot of a computer\" class=\"wp-image-137943 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig4-fake-booking-com-page.webp\"><figcaption class=\"wp-element-caption\">Figure 4. A screenshot of the fake Booking.com webpage, with the fake CAPTCHA overlay outlining the ClickFix process.<\/figcaption><\/figure>\n<p>The command downloads and launches malicious code through <em>mshta.exe<\/em>:<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig5-sample-command.webp\" alt=\"A black letter on a white background\" class=\"wp-image-137944 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig5-sample-command.webp\"><figcaption class=\"wp-element-caption\">Figure 5. An example of the mshta.exe command that the targeted user launches.<\/figcaption><\/figure>\n<p>This campaign delivers multiple families of commodity malware, including XWorm, Lumma stealer, VenomRAT, AsyncRAT, Danabot, and NetSupport RAT. Depending on the specific payload, the specific code launched through <em>mshta.exe<\/em> varies. Some samples have downloaded PowerShell, JavaScript, and portable executable (PE) content.<\/p>\n<p>All these payloads include capabilities to steal financial data and credentials for fraudulent use, which is a hallmark of Storm-1865 activity. In 2023, Storm-1865 targeted hotel guests using Booking.com with similar social engineering techniques and malware. In 2024, Storm-1865 targeted buyers using e-commerce platforms with phishing messages leading to fraudulent payment webpages. The addition of ClickFix to this threat actor\u2019s tactics, techniques, and procedures (TTPs) shows how Storm-1865 is evolving its attack chains to try to slip through conventional security measures against phishing and malware.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig6-attack-chain.webp\" alt=\"A diagram of a computer program\" class=\"wp-image-137945 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig6-attack-chain.webp\"><figcaption class=\"wp-element-caption\">Figure 6. Diagram illustrating the stages of the infection process in this campaign.<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"attribution\">Attribution<\/h2>\n<p>The threat actor that Microsoft tracks as Storm-1865 encapsulates a cluster of activity conducting&nbsp;phishing campaigns, leading to payment data theft and fraudulent charges. These campaigns have been ongoing with increased volume since at least early 2023 and involve messages sent through vendor platforms, such as online travel agencies and e-commerce platforms, and email services, such as Gmail or iCloud Mail.<\/p>\n<h2 class=\"wp-block-heading\" id=\"recommendations\">Recommendations<\/h2>\n<p>Users can follow the recommendations below to spot phishing activity. Organizations can reduce the impact of phishing attacks by educating users on recognizing these scams.<\/p>\n<p><strong>Check the sender\u2019s email address to ensure it\u2019s legitimate.<\/strong>&nbsp;Assess whether the sender is categorized as first-time, infrequent, or marked as&nbsp;\u201c[External]\u201d&nbsp;by your email provider. Hover over the address to ensure that the full address is legitimate. Keep in mind that legitimate organizations do not send unsolicited email messages or make unsolicited phone calls to request personal or financial information. Always navigate to those organizations directly to sign into your account.<\/p>\n<p><strong>Contact the service provider directly.<\/strong>&nbsp;If you receive a suspicious email or message, contact the service provider directly using official contact forms listed on the official website.<\/p>\n<p><strong>Be wary of urgent calls to action or threats.<\/strong>&nbsp;Remain cautious of email notifications that call to click, call, or open an attachment immediately. Phishing attacks and scams often create a false sense of urgency to trick targets into acting without first scrutinizing the message\u2019s legitimacy.<\/p>\n<p><strong>Hover over links to observe the full URL.<\/strong>&nbsp;Sometimes, malicious links are embedded into an email to trick the recipient. Simply clicking the link could let a threat actor download malware onto your device. Before clicking a link, ensure the full URL is legitimate. For best practice, rather than following a link from an email, search for the company website directly in your browser and navigate from there.<\/p>\n<p><strong>Search for typos.<\/strong>&nbsp;Phishing emails often contain typos, including within the body of the email, indicating that the sender is not a legitimate, professional source, or within the email domain or URL, as mentioned previously. Companies rarely send out messages without proofreading content, so multiple&nbsp;spelling and grammar mistakes can signal a scam message. In addition, check for very subtle misspellings of legitimate domains, a technique known as typosquatting. For example, you might see <em>micros0ft[.]com<\/em>, where the second <em>o<\/em> has been replaced by <em>0<\/em>, or <em>rnicrosoft[.]com<\/em>, where the <em>m<\/em> has been replaced by <em>r<\/em> and <em>n<\/em>.<\/p>\n<p>Microsoft recommends the following mitigations to reduce the impact of this threat.<\/p>\n<ul class=\"wp-block-list\">\n<li>Pilot and deploy&nbsp;<a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/authentication\/concept-authentication-methods\" target=\"_blank\" rel=\"noreferrer noopener\">phishing-resistant authentication methods<\/a>&nbsp;for users.<\/li>\n<li>Enforce multi-factor authentication (MFA) on all accounts, remove users excluded from MFA, and strictly&nbsp;<a href=\"https:\/\/learn.microsoft.com\/entra\/id-protection\/howto-identity-protection-configure-mfa-policy\" target=\"_blank\" rel=\"noreferrer noopener\">require MFA<\/a>&nbsp;from all devices in all locations at all times.<\/li>\n<li>Configure Microsoft Defender for Office 365 to&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-office-365\/safe-links-about\" target=\"_blank\" rel=\"noreferrer noopener\">recheck links on click<\/a>. Safe Links provides URL scanning and rewriting of inbound email messages in mail flow, and time-of-click verification of URLs and links in email messages, other Microsoft 365 applications such as Teams, and other locations such as SharePoint Online. Safe Links scanning occurs in addition to the regular&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/anti-spam-protection-about\" target=\"_blank\" rel=\"noreferrer noopener\">anti-spam<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/anti-malware-protection-about\" target=\"_blank\" rel=\"noreferrer noopener\">anti-malware<\/a>&nbsp;protection in inbound email messages in Microsoft Exchange Online Protection (EOP). Safe Links scanning can help protect your organization from malicious links used in phishing and other attacks.<\/li>\n<li>Encourage users to use Microsoft Edge and other web browsers that support&nbsp;<a href=\"https:\/\/learn.microsoft.com\/deployedge\/microsoft-edge-security-smartscreen\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Defender SmartScreen<\/a>, which identifies and blocks malicious websites, including phishing sites, scam sites, and sites that host malware.<\/li>\n<li>Turn on&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/cloud-protection-microsoft-defender-antivirus\" target=\"_blank\" rel=\"noreferrer noopener\">cloud-delivered protection<\/a>&nbsp;in Microsoft Defender Antivirus or the equivalent for your antivirus product to cover rapidly evolving attack tools and techniques. Cloud-based machine learning protections block a majority of new and unknown variants.<\/li>\n<li>Enable&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/enable-network-protection\" target=\"_blank\" rel=\"noreferrer noopener\">network protection<\/a>&nbsp;to prevent applications or users from accessing malicious domains and other malicious content on the internet.<\/li>\n<li>Enable&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/automated-investigations\">investigation and remediation<\/a>&nbsp;in full automated mode to allow Microsoft Defender for Endpoint to take immediate action on alerts to resolve breaches, significantly reducing alert volume.<\/li>\n<li>Enable <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/zero-hour-auto-purge\">Zero-hour auto purge (ZAP)<\/a> in Office 365 to quarantine sent mail in response to newly acquired threat intelligence and retroactively neutralize malicious phishing, spam, or malware messages that have already been delivered to mailboxes.<\/li>\n<\/ul>\n<p>Microsoft Defender XDR customers can turn on&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/attack-surface-reduction\" target=\"_blank\" rel=\"noreferrer noopener\">attack surface reduction rules<\/a>&nbsp;to prevent common attack techniques:<\/p>\n<h2 class=\"wp-block-heading\" id=\"detection-details\">Detection details<\/h2>\n<p>Microsoft Defender XDR customers can refer to the list of applicable detections below. Microsoft Defender XDR coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog.<\/p>\n<p>Customers with provisioned access can also use <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-in-microsoft-365-defender\">Microsoft Security Copilot in Microsoft Defender<\/a> to investigate and respond to incidents, hunt for threats, and protect their organization with relevant threat intelligence.<\/p>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-antivirus\">Microsoft Defender Antivirus<\/h3>\n<p>Microsoft Defender Antivirus detects threat components as the following malware:<\/p>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-for-endpoint\">Microsoft Defender for Endpoint<\/h3>\n<p>The following alerts might indicate threat activity associated with this threat. These alerts, however, can be triggered by unrelated threat activity:<\/p>\n<ul class=\"wp-block-list\">\n<li>Suspicious command in RunMRU registry<\/li>\n<li>Suspicious PowerShell command line<\/li>\n<li>Use of living-off-the-land binary to run malicious code<\/li>\n<li>Possible theft of passwords and other sensitive web browser information<\/li>\n<li>Suspicious DPAPI Activity<\/li>\n<li>Suspicious mshta process launched<\/li>\n<li>Suspicious phishing activity detected<\/li>\n<\/ul>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-for-office-365\">Microsoft Defender for Office 365<\/h3>\n<p>Microsoft Defender for Office 365 detects malicious activity associated with this threat through the following alerts:<\/p>\n<ul class=\"wp-block-list\">\n<li>This URL has known registrant pattern for malicious activity.<\/li>\n<li>This URL impersonates booking.com<\/li>\n<li>This PDF has generic phishing traits.<\/li>\n<li>This URL has generic phishing traits.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"microsoft-security-copilot\">Microsoft Security Copilot<\/h2>\n<p>Security Copilot customers can use the standalone experience to <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/prompting-security-copilot#create-your-own-prompts\">create their own prompts<\/a> or run the following <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/using-promptbooks\">pre-built promptbooks<\/a> to automate incident response or investigation tasks related to this threat:<\/p>\n<ul class=\"wp-block-list\">\n<li>Incident investigation<\/li>\n<li>Microsoft User analysis<\/li>\n<li>Threat actor profile<\/li>\n<li>Threat Intelligence 360 report based on MDTI article<\/li>\n<li>Vulnerability impact assessment<\/li>\n<\/ul>\n<p>Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.<\/p>\n<h2 class=\"wp-block-heading\" id=\"threat-intelligence-reports\">Threat intelligence reports<\/h2>\n<p>Microsoft customers can use the following reports in Microsoft products to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.<\/p>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-threat-intelligence\">Microsoft Defender Threat Intelligence<\/h3>\n<p>Microsoft Security Copilot customers can also use the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/security-copilot-and-defender-threat-intelligence?bc=%2Fsecurity-copilot%2Fbreadcrumb%2Ftoc.json&amp;toc=%2Fsecurity-copilot%2Ftoc.json#turn-on-the-security-copilot-integration-in-defender-ti\">Microsoft Security Copilot integration<\/a> in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/using-copilot-threat-intelligence-defender-xdrhttps:\/security.microsoft.com\/intel-explorer\/articles\/67d03ba9\">embedded experience<\/a> in the Microsoft Defender portal to get more information about this threat actor.<\/p>\n<h2 class=\"wp-block-heading\" id=\"hunting-queries\">Hunting queries<\/h2>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-xdr\">Microsoft Defender XDR<\/h3>\n<p>Microsoft Defender XDR customers can run the following query to find related activity in their networks:<\/p>\n<p><strong>Network connections to known C2 infrastructure related to this activity<\/strong><\/p>\n<p>Look for network connections with known C2 infrastructure.<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"23\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nlet c2Servers = dynamic(['92.255.57.155','147.45.44.131','176.113.115.170','31.177.110.99','185.7.214.54','176.113.115.225','87.121.221.124','185.149.146.164']);\nDeviceNetworkEvents\n| where RemoteIP has_any(c2Servers)\n| project Timestamp, DeviceId, DeviceName, LocalIP, RemoteIP, InitiatingProcessFileName, InitiatingProcessCommandLine\n<\/pre>\n<\/div>\n<h3 class=\"wp-block-heading\" id=\"microsoft-sentinel\">Microsoft Sentinel<\/h3>\n<p>Microsoft Sentinel customers can use the TI Mapping analytics (a series of analytics all prefixed with \u2018TI map\u2019) to automatically match the malicious domain indicators mentioned in this blog post with data in their workspace. If the TI Map analytics are not currently deployed, customers can install the Threat Intelligence solution from the <a href=\"https:\/\/learn.microsoft.com\/azure\/sentinel\/sentinel-solutions-deploy\">Microsoft Sentinel Content Hub<\/a> to have the analytics rule deployed in their Sentinel workspace.<\/p>\n<p>Below are the queries using&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/sentinel\/normalization\" target=\"_blank\" rel=\"noreferrer noopener\">Sentinel Advanced Security Information Model (ASIM) functions<\/a>&nbsp;to hunt threats across both Microsoft first-party and third-party data sources. ASIM also supports deploying parsers to specific workspaces&nbsp;<a href=\"https:\/\/aka.ms\/DeployASIM\">from GitHub<\/a>, using an ARM template or manually.<\/p>\n<p>Hunt normalized Network Session events using the ASIM unifying parser&nbsp;<em>_Im_NetworkSession<\/em>&nbsp;for IOCs:<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"25\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nlet lookback = 30d;\nlet ioc_ip_addr = dynamic(['92.255.57.155','147.45.44.131','176.113.115.170','31.177.110.99','185.7.214.54','176.113.115.225','87.121.221.124','185.149.146.164']); _Im_NetworkSession(starttime=todatetime(ago(lookback)), endtime=now())\n| where DstIpAddr in (ioc_ip_addr) or DstDomain has_any (ioc_domains)\n| summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, DstDomain, Dvc, EventProduct, EventVendor <\/pre>\n<\/div>\n<p>Hunt normalized Web Session events using the ASIM unifying parser&nbsp;<em>_Im_WebSession<\/em>&nbsp;for IOCs:<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"25\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nlet lookback = 30d;\nlet ioc_ip_addr = dynamic(['92.255.57.155','147.45.44.131','176.113.115.170','31.177.110.99','185.7.214.54','176.113.115.225','87.121.221.124','185.149.146.164']); _Im_WebSession(starttime=todatetime(ago(lookback)), endtime=now())\n| where DstIpAddr has_any (ioc_ip_addr) | summarize imWS_mintime=min(TimeGenerated), imWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, Url, Dvc, EventProduct, EventVendor\n<\/pre>\n<\/div>\n<p>Hunt normalized File events using the ASIM unifying parser&nbsp;<em>imFileEvent<\/em> for IOCs:<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"15\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nlet ioc_sha_hashes =dynamic([\"01ec22c3394eb1661255d2cc646db70a66934c979c2c2d03df10127595dc76a6\",\" f87600e4df299d51337d0751bcf9f07966282be0a43bfa3fd237bf50471a981e \",\"0c96efbde64693bde72f18e1f87d2e2572a334e222584a1948df82e7dcfe241d\"]); imFileEvent | where SrcFileSHA256 in (ioc_sha_hashes) or TargetFileSHA256 in (ioc_sha_hashes) | extend AccountName = tostring(split(User, @'\\')[1]), AccountNTDomain = tostring(split(User, @'\\')[0]) | extend AlgorithmType = \"SHA256\"\n<\/pre>\n<\/div>\n<h2 class=\"wp-block-heading\" id=\"indicators-of-compromise\">Indicators of compromise<\/h2>\n<figure class=\"wp-block-table table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"11\">\n<tr>\n<td><strong>Indicator<\/strong><\/td>\n<td><strong>Type<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>92.255.57[.]155<\/td>\n<td>IP address<\/td>\n<td>C2 server delivering XWorm<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>147.45.44[.]131<\/td>\n<td>IP address<\/td>\n<td>C2 server delivering Danabot<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>176.113.115[.]170<\/td>\n<td>IP address<\/td>\n<td>C2 server delivering LummaStealer<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>31.177.110[.]99<\/td>\n<td>IP address<\/td>\n<td>C2 server delivering Danabot<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>185.7.214[.]54<\/td>\n<td>IP address<\/td>\n<td>C2 server delivering XWorm<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>176.113.115[.]225<\/td>\n<td>IP address<\/td>\n<td>C2 server delivering LummaStealer<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>87.121.221[.]124<\/td>\n<td>IP address<\/td>\n<td>C2 server delivering Danabot<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>185.149.146[.]164<\/td>\n<td>IP address<\/td>\n<td>C2 server delivering AsyncRAT<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>01ec22c3394eb1661255d2cc646db70a66934c979c2c2d03df10127595dc76a6 &nbsp;<\/td>\n<td>File hash (SHA-256)<\/td>\n<td>Danabot malware<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>f87600e4df299d51337d0751bcf9f07966282be0a43bfa3fd237bf50471a981e<\/td>\n<td>File hash (SHA-256)<\/td>\n<td>Danabot malware<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>0c96efbde64693bde72f18e1f87d2e2572a334e222584a1948df82e7dcfe241d &nbsp;<\/td>\n<td>File hash (SHA-256)<\/td>\n<td>Danabot malware<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"references\">References<\/h2>\n<h2 class=\"wp-block-heading\" id=\"learn-more\">Learn more<\/h2>\n<p>For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog:&nbsp;<a href=\"https:\/\/aka.ms\/threatintelblog\">https:\/\/aka.ms\/threatintelblog<\/a>.<\/p>\n<p>To get notified about new publications and to join discussions on social media, follow us on LinkedIn at <a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence\">https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence<\/a>, and on X (formerly Twitter) at&nbsp;<a href=\"https:\/\/x.com\/MsftSecIntel\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/x.com\/MsftSecIntel<\/a>.<\/p>\n<p>To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast: <a href=\"https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence\">https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence<\/a>.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/03\/13\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Starting in December 2024, leading up to some of the busiest travel days, Microsoft Threat Intelligence identified a phishing campaign that impersonates online travel agency Booking.com and targets organizations in the hospitality industry. The campaign uses a social engineering technique called ClickFix to deliver multiple credential-stealing malware in order to conduct financial fraud and theft. [&#8230;]<br \/>\nThe post Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":58297,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[5449,10798],"class_list":["post-58296","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-credential-theft","tag-storm"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-03-13T15:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig1-sample-phishing-email.webp\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware\",\"datePublished\":\"2025-03-13T15:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/\"},\"wordCount\":2159,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware.webp\",\"keywords\":[\"Credential Theft\",\"Storm\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/\",\"name\":\"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware.webp\",\"datePublished\":\"2025-03-13T15:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware.webp\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware.webp\",\"width\":1008,\"height\":327},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Credential Theft\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/credential-theft\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/","og_locale":"en_US","og_type":"article","og_title":"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-03-13T15:00:00+00:00","og_image":[{"url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/03\/Fig1-sample-phishing-email.webp","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware","datePublished":"2025-03-13T15:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/"},"wordCount":2159,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware.webp","keywords":["Credential Theft","Storm"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/","url":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/","name":"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware.webp","datePublished":"2025-03-13T15:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware.webp","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware.webp","width":1008,"height":327},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Credential Theft","item":"https:\/\/www.threatshub.org\/blog\/tag\/credential-theft\/"},{"@type":"ListItem","position":3,"name":"Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=58296"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58296\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/58297"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=58296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=58296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=58296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}