Hotel credit card wrong transaction email malware attack

Filed Under: Malware, Spam

Be on your guard! Emails claiming to be from a hotel about a wrong transaction on your credit card are being spammed worldwide - with the intention of infecting your computer with a malware.

Here's a typical example. In this case it claims to come from the booking department of the Hotel Swissotel in Chicago:

Hotel malicious email

Hotel Swissotel Chicago made wrong transaction

Dear client!

We are sorry to inform you that on July 26th, 2011 Hotel transaction debiting from your account for an overall amount of $1857.
This partner hotel was divested accreditation in Booking Company with reference of noncompliance of the service contract.
Please see the attached form. You need to fill it in and contact your bank for the return of funds.
In the attachment you will find expense sheet with the sum of wrong transaction writing-down.
Company just mediates and bears no responsibility for any money transactions made by Hotel.
Sorry for the inconvenience. We trust you can solve this unpleasant problem.

Manager: Genaro Dunwiddie

The name of the hotel, the amount of money and the manager's name can vary from email to email. Similarly the subject lines vary as you can see in the examples below:

Hotel malicious email subject lines

But all of the emails we have seen so far do claim to have a booking refund attached in a ZIP file, and this is where the malware attack is contained.

Of course, even if you weren't staying at the hotel on July 26th you might still be concerned that your credit card has been abused by someone who *was* enjoying luxurious room service, unfettered use of the mini-bar and a complimentary newspaper.

Recipients who are intrigued to find that they may be owed some money might open the ZIP file without thinking of the possible consequences, and infect their computer with a Trojan horse.

Once infected, remote hackers can take control of your computer - potentially using it to spam out other attacks or to steal information from you.

Sophos detects the malware as Troj/Zbot-AXZ and the ZIP file itself as Troj/Invo-Zip.

Make sure that your anti-virus defences are up-to-date and always be suspicious of unsolicited emails that try to lure you into opening attachments. It could be a ploy by a hacker to hijack your computer.

, , , , ,

You might like

One Response to Hotel credit card wrong transaction email malware attack

  1. David ยท 1489 days ago

    Why whenever I get one of these do they spoil it by including several other addressees - who in an address book would be close to my surname? As if I would believe that we could all have suffered exactly the same unpleasant problem at the same hotel for the same amount!

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

About the author

Graham Cluley runs his own award-winning computer security blog at, and is a veteran of the anti-virus industry having worked for a number of security companies since the early 1990s. Now an independent security analyst, he regularly makes media appearances and gives computer security presentations. Follow him on Twitter at @gcluley