The Latest in IT Security

Hotel booking confirmation emails aim to infect your computer. Watch out!


Be on your guard against emails that claim to be about a hotel booking that you never made – you could be putting your computer at risk of infection by malware.

Emails have been spammed out claiming to be a confirmation from the website about a hotel reservation.

Chances are that if you received an email like the following you would be at the very least curious, and might be tempted to click on the attached file.

Hotel booking malware

A typical email reads:

Subject: [Fwd: Hotel booking confirmation 2930566265]

Attached file:

Message body:

Booking confirmation 8356693431

Date: Tuesday , 29 May ‘2012


We have received a reservation for your hotel.

Please refer to attached file now to acknowledge the reservation and see the reservation details.

Arrival: Tuesday, 05 June 2012

Number of rooms: 1

If you have any questions regarding this reservation, please feel free to contact us. Telephone: English support 1 888 850 4649, Spanish support 1 866 938 1298; Fax 1 866 814 1719; Email: [email protected]

Yours sincerely,

Of course, opening the attachment would be a big mistake, as the emails don’t really come from

The attached .ZIP file contains a Trojan horse designed to infect your computer. Sophos products detect the malware as Mal/BredoZp-B and Troj/Inject-VI.

Long time readers of Naked Security will be only too familiar with malware attacks associated with hotels. For instance, in the past we have seen attempts to infect computers via emails disguised as hotel credit card transactions.

The advice remains the same.

You should always be suspicious of email attachments that are sent to you out of the blue. Make sure that your anti-virus product is updated, that you have the latest security patches, and tell your friends to think twice before opening unknown attachments.

Leave a reply



Mission-Critical Broadband – Why Governments Should Partner with Commercial Operators:
Many governments embrace mobile network operator (MNO) networks as ...

ARA at Scale: How to Choose a Solution That Grows With Your Needs:
Application release automation (ARA) tools enable best practices in...

The Multi-Model Database:
Part of the “new normal” where data and cloud applications are ...



Latest Comments