Fake Booking Websites Deliver LummaStealer Malware - Beware!

Hackers have launched a new attack using fake hotel and travel booking websites to spread LummaStealer malware. Disguised as legitimate booking confirmation pages, these fraudulent sites trick users into running harmful commands that compromise their personal and financial information.
- Fake Booking Websites – Cybercriminals create phishing sites that look like real travel booking pages.
- Deceptive CAPTCHA Verification – Instead of a real CAPTCHA, users are told to run a command in Windows, which starts the malware infection.
- Targeted Travel Locations – Initially, the scam focused on Palawan, Philippines, but later expanded to Munich, Germany, showing a global attack pattern.
- PowerShell-Based Malware Installation – The malware uses a PowerShell command to bypass security measures and infect systems.
- LummaStealer Malware – Once installed, this malware steals passwords, banking details, and other sensitive information.
- Advanced Evasion Techniques – Attackers use Binary Padding (increasing file size) and Obfuscation (hiding malware in encrypted scripts) to avoid detection.
Hackers are constantly evolving their tactics, and fake booking websites have become a new weapon for spreading malware. The LummaStealer campaign highlights the risks of online travel scams and the importance of cybersecurity awareness.
Stay cautious, verify websites, and never execute unknown commands to keep your data safe!
Comment(s)
Categories
- Other (43)
- Ransomware (154)
- Events and News (27)
- Features (45)
- Security (485)
- Tips (79)
- Google (28)
- Achievements (11)
- Products (36)
- Activation (7)
- Dealers (1)
- Bank Phishing (50)
- Malware Alerts (231)
- Cyber Attack (299)
- Data Backup (13)
- Data Breach (127)
- Phishing (165)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (71)
- Android Security (77)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (70)
- Social Media (8)
- vulnerability (74)
- Hacker (38)
- Spyware (12)
- Windows (8)
- Microsoft (25)
- Uber (1)
- YouTube (1)
- Trojan (4)
- Website hacks (10)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (8)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (9)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (2)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (40)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (29)
Recent Posts
Archive
Tags
cybersecurity
cybercrime
cyber attack
phishing
phishing attacks
data breach
cyber threats
data theft
phishing attack
malware
android malware
credential theft
ransomware
cyber fraud
cybersecurity threats
financial fraud
ransomeware
social engineering
financial security
cyber security
#cybersecurity
data protection
cyberthreats
phishingattack
network security
cyber threat
malware distribution
identity theft
security vulnerabilities
cert-in
data stealing
ransomware attacks
cyber crime
phishing scam
online fraud
data security
ddos attack
critical vulnerability
phishing email
ransomware attack
microsoft
cyber attacks
digital safety
twitter
ddos
india
cybercriminals
cyberattack
trojan
malware attack