www.bleepingcomputer.com Homoglyph Phishing Campaign Targets Booking.com Users
Article Content
- •Threat actors use Unicode homoglyphs to create deceptive URLs.
- •Victims are redirected to a malicious site that installs malware.
- •This phishing tactic has targeted Booking.com users multiple times.
A new phishing campaign exploits Unicode homoglyphs to mimic legitimate Booking.com URLs, using the Japanese hiragana character 'ん' to deceive users. This character can appear as a forward slash in certain fonts, making the malicious links look authentic. Victims clicking on these links are redirected to a fraudulent site, www-account-booking[.]com, which delivers a malicious MSI installer. This installer can potentially drop various malware, including infostealers and remote access trojans. The campaign has been linked to previous phishing attempts targeting Booking.com customers, indicating a persistent threat. Security experts warn that such homoglyph attacks are becoming more common, leveraging psychological tricks to bypass user scrutiny. Users are advised to be vigilant and check URLs closely before clicking.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Booking.com in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…