Skip to content
Homoglyph Phishing Campaign Targets Booking.com Users

Homoglyph Phishing Campaign Targets Booking.com Users

First seen 20 Sep 2026, 10:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 11:55 UTC
  • Threat actors use Unicode homoglyphs to create deceptive URLs.
  • Victims are redirected to a malicious site that installs malware.
  • This phishing tactic has targeted Booking.com users multiple times.

A new phishing campaign exploits Unicode homoglyphs to mimic legitimate Booking.com URLs, using the Japanese hiragana character 'ん' to deceive users. This character can appear as a forward slash in certain fonts, making the malicious links look authentic. Victims clicking on these links are redirected to a fraudulent site, www-account-booking[.]com, which delivers a malicious MSI installer. This installer can potentially drop various malware, including infostealers and remote access trojans. The campaign has been linked to previous phishing attempts targeting Booking.com customers, indicating a persistent threat. Security experts warn that such homoglyph attacks are becoming more common, leveraging psychological tricks to bypass user scrutiny. Users are advised to be vigilant and check URLs closely before clicking.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-20
New homoglyph phishing campaign identified
Researchers discovered a phishing campaign using the hiragana character 'ん' to mimic Booking.com URLs, leading to malware distribution.
BleepingComputer
2026-09-20
Homoglyph attack awareness raised
The Guardian published an article explaining homoglyph attacks and how they can deceive users, referencing the Booking.com phishing campaign.
Theguardian

More articles in this cluster (2)

Following this threat?

Track Booking.com in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed