<ul data-eligibleForWebStory="true">Hackers are targeting holidaymakers with remote access trojans through fake Booking.com websites.The fake sites mimic Booking.com but have blurred content and a deceptive cookie banner.Clicking 'Accept cookies' triggers a download of a malicious JavaScript file installing a RAT called XWorm.XWorm allows attackers to control compromised devices, access files, webcams, microphones, disable security tools, deploy malware, and steal data.The campaign was first spotted in peak summer booking period Q1 2025, exploiting users' 'click fatigue' during rush times.Users are advised to slow down when browsing, avoid clicking on links in emails or social media, and type website addresses manually.