Threat Actor Impersonates Booking.com in Phishing Scheme post, maart 14, 2025maart 17, 2025 Microsoft detailed a sophisticated campaign that relies on a social engineering technique, “ClickFix,” in which a phisher uses security verification like captcha to give the target a false sense of safety. That’s according to Microsoft, which published threat intelligence on March 13 regarding a threat actor tracked as Storm-1865. The actor was observed using ClickFix — a technique describing when “a threat actor attempts to take advantage of human problem-solving tendencies by displaying fake error messages or prompts that instruct target users to fix issues by copying, pasting, and launching commands that eventually result in the download of malware” — in attacks primarily targeting the hospitality industry. Storm-1865 Impersonates Booking.com in Phishing Scheme: Threat Actor Impersonates Booking.com in Phishing Scheme phishing 2025