Fake Booking Websites Deliver LummaStealer Malware - Beware!

Hackers have launched a new attack using fake hotel and travel booking websites to spread LummaStealer malware. Disguised as legitimate booking confirmation pages, these fraudulent sites trick users into running harmful commands that compromise their personal and financial information.
- Fake Booking Websites – Cybercriminals create phishing sites that look like real travel booking pages.
- Deceptive CAPTCHA Verification – Instead of a real CAPTCHA, users are told to run a command in Windows, which starts the malware infection.
- Targeted Travel Locations – Initially, the scam focused on Palawan, Philippines, but later expanded to Munich, Germany, showing a global attack pattern.
- PowerShell-Based Malware Installation – The malware uses a PowerShell command to bypass security measures and infect systems.
- LummaStealer Malware – Once installed, this malware steals passwords, banking details, and other sensitive information.
- Advanced Evasion Techniques – Attackers use Binary Padding (increasing file size) and Obfuscation (hiding malware in encrypted scripts) to avoid detection.
Hackers are constantly evolving their tactics, and fake booking websites have become a new weapon for spreading malware. The LummaStealer campaign highlights the risks of online travel scams and the importance of cybersecurity awareness.
Stay cautious, verify websites, and never execute unknown commands to keep your data safe!
Comment(s)
Categories
- Other (42)
- Ransomware (141)
- Events and News (27)
- Features (45)
- Security (462)
- Tips (79)
- Google (23)
- Achievements (11)
- Products (34)
- Activation (7)
- Dealers (1)
- Bank Phishing (44)
- Malware Alerts (206)
- Cyber Attack (254)
- Data Backup (11)
- Data Breach (94)
- Phishing (154)
- Securty Tips (1)
- Browser Hijack (18)
- Adware (15)
- Email And Password (67)
- Android Security (67)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (71)
- Hacking (57)
- Social Media (8)
- vulnerability (56)
- Hacker (31)
- Spyware (9)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (4)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (7)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (11)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (9)
- Impersonation phishing (1)
- DDoS (5)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
Recent Posts
Archive
Tags
cyber attack
phishing
data breach
cyber threats
phishing attacks
ransomware
phishing attack
ransomeware
android malware
malware
cyber security
data theft
phishingattack
cyberthreats
financial security
data stealing
cybercrime
network security
ddos attack
data security
critical vulnerability
cyber fraud
trojan
net protector total security
data protection
cert-in
financial fraud
phishing email
microsoft
lockbit
cybercriminals
cyber crime
ddos
phishing scam
cyber threat
india
twitter
android
ransomware attacks
cryptojacking
winrar
malicious apps
pakistan-backed hacker
android apps
email phishing
play store
server security
databreach
clop
ransomware attack