Executive Summary
In late 2025, the hospitality sector was targeted by a sophisticated, large-scale phishing campaign involving ClickFix-style lures that tricked hotel managers into revealing their credentials. Attackers leveraged compromised email accounts to distribute malicious links to numerous hotel establishments, leading victims to phishing sites that mimicked familiar workflow tools. Credential theft enabled deployment of PureRAT malware, which provided remote access to internal hotel systems and enabled lateral movement, resulting in compromised operations and data exposure for multiple organizations.
This incident demonstrates the increasing use of advanced social engineering in credential-focused attacks against the hospitality industry. With phishing campaigns growing more convincing and commodity RATs like PureRAT widely available, organizations in high-turnover sectors face mounting risk from credential-based breaches and follow-on malware infections.
Why This Matters Now
ClickFix-style phishing is proliferating with tailored lures and remote access trojans, making it critical for businesses—especially those in service industries—to strengthen credential protection, visibility, and lateral movement controls before attackers exploit low-friction entry points.
Attack Path Analysis
The attackers initiated access by sending targeted phishing emails to hotel managers, tricking victims into entering credentials on spoofed ClickFix pages and delivering PureRAT malware. Compromised credentials and endpoint access may have enabled privilege escalation within hospitality IT systems or cloud environments. Using remote access provided by PureRAT, adversaries likely moved laterally to access sensitive hotel systems and data. The malware established command and control channels to receive instructions and exfiltrate data, leveraging unmonitored egress paths. Stolen data, including credentials and business documents, was exfiltrated to attacker infrastructure. The attack resulted in credential theft, potential further compromise of downstream systems, and increased risk of business disruption.
Kill Chain Progression
Initial Compromise
Description
Hotel managers received phishing emails from a compromised account, leading to credential harvesting and PureRAT malware deployment via malicious ClickFix-style pages.
Related CVEs
CVE-2025-10035
CVSS 10A command injection vulnerability in Fortra GoAnywhere MFT allows unauthenticated remote code execution.
Affected Products:
Fortra GoAnywhere MFT – < 7.8.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Valid Accounts
User Execution: Malicious File
Command and Scripting Interpreter
Credentials from Web Browsers
Obfuscated Files or Information
Ingress Tool Transfer
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong authentication for users and administrators
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Adopt phishing-resistant authentication
Control ID: Identity Pillar: Phishing Resistance
NIS2 Directive – Technical and Organisational Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Hospitality
Direct target of ClickFix phishing campaign compromising hotel manager credentials, requiring immediate egress security and threat detection capabilities to prevent PureRAT malware deployment.
Information Technology/IT
Critical infrastructure vulnerabilities exposed through credential harvesting attacks, necessitating zero trust segmentation and multicloud visibility to protect client systems from lateral movement.
Computer/Network Security
Industry expertise required to combat sophisticated ClickFix phishing techniques, implementing inline IPS and anomaly detection solutions to protect hospitality sector clients.
Financial Services
Payment processing systems at risk through compromised hotel establishments, requiring encrypted traffic protection and compliance adherence to prevent financial data exfiltration.
Sources
- Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malwarehttps://thehackernews.com/2025/11/large-scale-clickfix-phishing-attacks.htmlVerified
- Phishing campaign impersonates Booking.com, delivers a suite of credential-stealing malwarehttps://www.microsoft.com/en-us/security/blog/2025/03/13/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware/Verified
- ClickFix Phishing Targets Hotel Systemshttps://cybermaterial.com/clickfix-phishing-targets-hotel-systems/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic security, and egress policy enforcement would have limited attackers' ability to move laterally, send data externally, and escalate privileges following the initial compromise. Network visibility, segmentation, and inline threat detection would have enabled earlier detection and containment of PureRAT and credential theft activities.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious phishing or malware-related activity would trigger alerts for immediate response.
Control: Zero Trust Segmentation
Mitigation: Lateral privilege escalation is contained by least privilege policies and workload isolation.
Control: East-West Traffic Security
Mitigation: Unapproved workload-to-workload lateral movement is blocked and flagged for investigation.
Control: Cloud Firewall (ACF)
Mitigation: Malicious outbound connections are detected and blocked at the network perimeter.
Control: Egress Security & Policy Enforcement
Mitigation: Sensitive data exfiltration attempts are detected and prevented.
Automated policy enforcement and real-time inspection limit business disruption and persistence.
Impact at a Glance
Affected Business Functions
- Reservations
- Customer Communications
- Payment Processing
Estimated downtime: 5 days
Estimated loss: $500,000
Unauthorized access to customer reservation details, including personal and payment information, leading to potential identity theft and financial fraud.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust Segmentation to limit movement using identity-based workload policies across cloud and on-prem environments.
- • Enforce strict east-west and egress filtering controls to block malicious C2 and data exfiltration attempts.
- • Leverage continuous anomaly detection and threat intelligence for early phishing and RAT activity identification.
- • Enable centralized multicloud visibility to monitor, alert on, and quickly investigate suspicious credential or network behaviors.
- • Regularly audit and update network, firewall, and application segmentation rules to ensure least privilege remains in effect across all business-critical systems.



