Story perspectives
Russian Hackers Target European Hotels with Advanced Malware
1/7/2026
23 2
1 of 1
Story summary
- Securonix, a cybersecurity firm, reports a multi-stage malware campaign targeting European hotels, using phishing emails that impersonate Booking.com to trick staff into executing malicious PowerShell commands and installing the DCRat remote access Trojan.
- The campaign has evolved to employ MSBuild techniques to bypass security and deliver DCRat payload.
- It appears focused on European companies during peak holiday seasons.
- Evidence suggests Russian threat actors, based on malware artifacts and language.
