Campaign record
Hotel lost-property phishing mail
Hotel lost-property phishing routed through open redirectors to fake CAPTCHA pages
- Status as last assessed
- Active
- First seen
- Unrecorded
- Last seen
- 2025-05-19
- Indicators
- 7
- Sources
- 1
- Targets
- Windows
- Fake CAPTCHA verification
- Hotel guest belongings
- Open redirector on a legitimate site
- Phishing email
Original research
- Trend Micro2025-05-19Vendor researchFirst account
Fake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
A phishing run aimed at hotels and other accommodation businesses used subject lines about property a departing guest had supposedly forgotten: passports, laptops, medical kit, an unlocked safe deposit box. The wording is formal and time-pressured. Some messages carried a link, others attached a PDF whose embedded link did the same work. Either way the recipient passed through an open redirector on an unrelated and well-regarded website before arriving at a page imitating a human-verification check, which placed a command on the clipboard and asked them to run it. Trend Micro names seven domains behind this lure, most of them rearrangements of the words guest, reserve, item and found. Endpoint telemetry in the report shows the chain in practice, with a mail client opening a browser at one of those domains.
What changed since publication
The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.
- Indicators checked
- 7 of 7
- Checks recorded
- 14
- Checks since publication
- 14
- Never checked
- 0
Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology.
Current recorded state
- 7 Unregistered
Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is Windows Run dialog (T1204.004), which 23 of the 44 published campaigns in this corpus also record (52%).
Indicators
7 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account or any overlap with another campaign in this corpus. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Hotel lost-property phishing mail”, campaign ID 0bd90ac4, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/0bd90ac4/hotel-guest-items-phishing-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.