Alpha Cyber

Behind the Booking.com Scam: ClickFix and a Phishing-as-a-Service Operation

Executive Summary A sophisticated phishing campaign dubbed “I Paid Twice” is actively targeting Booking.com hotels and their customers, abusing brand trust to deliver malware and remote access tooling.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Behind the Booking.com Scam: ClickFix and a Phishing-as-a-Service Operation

“I Paid Twice”: Inside the Booking.com Phishing Infrastructure Powering ClickFix Malware

Executive Summary

A sophisticated phishing campaign dubbed “I Paid Twice” is actively targeting Booking.com hotels and their customers, abusing brand trust to deliver malware and remote access tooling. What makes this campaign dangerous is not just the phishing lure, but the well-structured malicious service infrastructure behind it from redirect domains and scripted payload delivery to malware staging and command-and-control.

By mapping this infrastructure end-to-end, defenders gain visibility into how initial phishing clicks evolve into ClickFix malware execution and, ultimately, remote access and credential theft.

Threat Overview: From Phish to Full Compromise

The campaign begins with fraudulent Booking.com-themed messages sent to hotels and customers. These messages claim payment issues, booking confirmations, or required document reviews. Victims who click are silently redirected through a network of look-alike domains designed to evade detection and rotate quickly.

Once the victim interacts with the fake page, the attack transitions into the ClickFix delivery stage, where malicious scripts guide the user into executing a payload often disguised as a legitimate update or verification step.

This campaign demonstrates how modern phishing operations function as service-based ecosystems, not isolated attacks.

ClickFix Malware Technical Snapshot

PEStudio Clickfix B22 Overview

AttributeValue
Malware NameClickFix
File TypePE64
Operating SystemWindows (Vista+) AMD64
SignatureUnknown
VirusTotal Score42 malicious detections
LanguagePython
(Heuristic) LanguageJavaScript
CompilerMicrosoft Visual C/C++
ToolchainVisual Studio 2022
PackerPyInstaller (modified)
OverlayLarge compressed binary overlay
CompressionZLIB / Raw Deflate

Primary Hash (SHA1):
5c6da6ad7054e97ca9a2eeb0c79085c45bc5996e

What We Observed During Static Investigation

PEStudio Clickfix B22 Imports 28

While investigating the ClickFix payload, PeStudio highlights several red flags consistent with malicious loaders:

  • Suspicious API Imports such as CreateProcessW, WriteFile, and DeleteFileW suggest execution, persistence preparation, and cleanup activity.

  • High entropy overlays indicate payload hiding through compression and packing.

  • Unsigned PE with unknown signature, often associated with fast-moving malware campaigns.

  • Mixed scripting artifacts, aligning with Python-based loaders deploying JavaScript-assisted execution logic.

  • Anti-analysis indicators, including sandbox and virtual environment checks, to evade automated detection.

These findings align with ClickFix being a delivery and staging component, not just a standalone binary.

PEstudio Clickfix B22 Overlay Unkown Signature 

Malware Capabilities & Behavior Mapping

capa clickfix b22


MITRE ATT&CK Highlights


Defense Evasion

Obfuscated Files or Information (T1027)


Virtualization/Sandbox Evasion (T1497.001)


Discovery

File and Directory Discovery (T1083)


Process Discovery (T1057)


System Information Discovery (T1082)


Execution

Command and Scripting Interpreter (T1059)


Shared Modules (T1129)


Notable Capabilities Identified


XOR-encoded data handling


ZLIB compression and decompression


Runtime API linking


File system enumeration and manipulation


Process creation (including suspended processes)


Environment variable inspection and modification


Together, these behaviors indicate

loader-style malware

, designed to prepare the system for follow-on payloads such as

PureRAT

.

Why Infrastructure Visibility Matters

This campaign succeeds because it distributes risk across dozens of domains, redirectors, payload hosts, and C2 endpoints. Blocking a single URL or hash is not enough.

By correlating:

  • phishing redirect paths

  • PowerShell payload endpoints

  • malware staging servers

  • command-and-control nodes

defenders can disrupt the entire attack chain, not just individual indicators.

VirusTotal Clickfix b22 Graph

Indicators of Compromise (IOCs)

Recommendation: Block these indicators at email gateways, web proxies, EDR, and SIEM platforms.

ClickFix Cluster  – Initial Phishing Redirects

TypeIndicator
URLhxxps://headkickscountry[.]com/lz1y
URLhxxps://activatecapagm[.]com/j8r3
URLhxxps://homelycareinc[.]com/po7r
URLhxxps://byliljedahl[.]com/8anf
URLhxxps://jamerimprovementsllc[.]com/ao9o
URLhxxps://seedsuccesspath[.]com/6m8a
URLhxxps://zenavuurwerkofficial[.]com/62is
URLhxxps://brownsugarcheesecakebar[.]com/ajm4
URLhxxps://hareandhosta[.]com/95xh
URLhxxps://customvanityco[.]com/izsb
URLhxxps://byliljedahl[.]com/lv6q

ClickFix  PowerShell Payload Delivery

TypeIndicator
URLhxxps://ctrlcapaserc[.]com/bomla
URLhxxps://bknqsercise[.]com/bomla
URLhxxps://bkngssercise[.]com/bomla
URLhxxps://bkngpropadm[.]com/bomla
URLhxxps://cquopymaiqna[.]com/bomla
URLhxxps://emprotel[.]net[.]bo/updserc[.]zip
URLhxxps://cabinetifc[.]com/upseisser[.]zip

Cluster Domains (Phishing Infrastructure)

TypeIndicator
Domainwhooamisercisea[.]com
Domainwhooamisercise[.]com
Domainaidaqosmaioa[.]com
Domainbqknsieasrs[.]com
Domainupdate-infos616[.]com
Domainmccplogma[.]com
Domainmccp-logistics[.]com
Domaincquopymaiqna[.]com
Domaincontmasqueis[.]com
Domainupdate-info1676[.]com
Domainadmin-extranet-reservationsinfos[.]com
Domainctrlcapaserc[.]com
Domainbkngssercise[.]com
Domainbknqsercise[.]com
Domainbookingadmin-updateofmay2705[.]com
Domainbooking-reservationinfosid0251358[.]com

PureRAT Staging & C2

TypeIndicator
URLhxxps://ctrlcapaserc[.]com/loggqibkng
URLhxxps://bqknsieasrs[.]com/loggqibkng
IP:Port85.208.84[.]94:56001
IP:Port77.83.207[.]106:56001
Hash703355e8e93f30df19f7f7b8800bd623f1aee1f020c43a4a1e11e121c53b5dd1
Hash5301f5a3fb8649edb0a5768661d197f872d40cfe7b8252d482827ea27077c1ec
Hash64838e0a3e2711b62c4f0d2db5a26396ac7964e31500dbb8e8b1049495b5d1f3

Phishing Targeting Hotel Customers

TypeIndicator
URLhxxps://confirmation887-booking[.]com/17149438
URLhxxps://verifyguest02667-booking[.]com/17149438
URLhxxps://guest03442-booking[.]com/17149438
URLhxxps://confirmation8324-booking[.]com/17149438
URLhxxps://cardverify0006-booking[.]com/37858999
URLhxxps://verifycard45625-expedia[.]com/67764524

Final Thoughts

The “I Paid Twice” campaign highlights how phishing has evolved into modular, resilient service infrastructures that blend social engineering with malware delivery and remote access tooling.

Organizations in the hospitality sector and those protecting them must move beyond surface-level detection and focus on full attack-path visibility, correlating phishing, payload delivery, and command-and-control activity.

Blocking infrastructure, not just files, is now a defensive necessity.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]