The phishing page prompts for OTP codes sent via SMS | Image: Okta
Okta Threat Intelligence is sounding the alarm over a large-scale phishing campaign that has been actively impersonating major players in the hospitality and vacation rental sector. The campaign leverages malicious advertising, convincing login pages, and social engineering to compromise sensitive accounts used for hotel and property management services.
The attackers rely heavily on malicious search engine advertisements, particularly Google Search sponsored ads, to lure victims. According to Okta, βIn these attacks, targeted users are lured to highly deceptive phishing sites using malicious search engine advertisements, particularly sponsored ads on platforms like Google Search.β
These ads often appear above legitimate search results, using domains that mimic the names of trusted hospitality providers. βObserved domains used a typosquatting variation of the legitimate website. A user that navigates to one of these malicious domains is presented a fake login page.β

Okta confirmed that at least thirteen hospitality companies have been impersonated, including cloud-based property management and guest messaging platforms.
Once victims reach the phishing page, the attackersβ primary goal is credential harvesting. The fake portals are designed to collect usernames, email addresses, phone numbers, and passwords.
Okta notes, βThe observed activity demonstrates an intent to bypass or capture multi-factor authentication (MFA) codes. For instance, some phishing pages explicitly prompt for βOne time passwordβ or offer βSign in with SMS Codeβ and βEmail Codeβ options.β
Screenshots from the campaign show convincing clones of login portals for services like Airbnb and Oracle Hospitality. In some cases, victims are prompted to enter phone numbers, which then trigger requests for OTP codes sent via SMS.
A deeper look into the phishing pagesβ source code revealed Russian-language comments and error messages, suggesting the attackers may be Russian-speaking. Okta highlights the following snippet:
The error message translates to βRequest errorβ and the comment reads βWe start the request every 10 secondsβ. Combined with the use of a large Russian datacenter proxy provider for attacker sign-ins, the evidence points toward operators with ties to Russian infrastructure.
The phishing infrastructure is not just collecting credentialsβitβs also designed for tracking and analytics. Okta explains, βThe campaign also employs a beaconing technique for tracking and analytics. This allows the attacker to gather valuable real-time information about the victims who have landed on the phishing page, including visitor analytics, geolocation, session duration, bot detection, and status monitoring.β
Okta warns that organizations should monitor for suspicious login attempts, educate users about malicious search ads, and enforce phishing-resistant MFA methods to reduce exposure.
As the report emphasizes, βBased on the targeting and nature of the phishing lures, the campaign appears designed to compromise accounts for cloud-based property management and guest messaging platforms.β
Related Posts:
- Chameleon Banking Trojan Targets Hospitality Sector with Novel CRM Masquerade
- Sophos X-Ops Alerts: ‘Inhospitality’ Malspam Targets Hotels with Deceptive Tactics
- Data Breach at Okta Affects All Customer Support Users: Company Updates Scope
- Okta Patches Vulnerability (CVE-2024-9191) in Verify Desktop MFA for Windows
- Okta Patches Vulnerability Allowing Unauthorized Access
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!