[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/travel-themed-phishing/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/travel-themed-phishing/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Phishing Eager Travelers

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 9 min read  
Related Products  
[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Anna Chung](https://unit42.paloaltonetworks.com/author/anna-chung/)
  * [Swetha Balla](https://unit42.paloaltonetworks.com/author/swetha-balla/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 15, 2021

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [COVID](https://unit42.paloaltonetworks.com/tag/covid/)
  * [Dridex](https://unit42.paloaltonetworks.com/tag/dridex/)
  * [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/)
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [Tourism](https://unit42.paloaltonetworks.com/tag/tourism/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/travel-themed-phishing/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/travel-themed-phishing/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Phishing%20Eager%20Travelers&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ftravel-themed-phishing%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Ftravel-themed-phishing%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ftravel-themed-phishing%2F&title=Phishing%20Eager%20Travelers "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ftravel-themed-phishing%2F&text=Phishing%20Eager%20Travelers "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Ftravel-themed-phishing%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Phishing%20Eager%20Travelers%20https%3A%2F%2Funit42.paloaltonetworks.com%2Ftravel-themed-phishing%2F "Share in Mastodon")

## Executive Summary

Threat actors have always been adept at keeping abreast of worldwide trends -- ranging from geopolitical to technical -- and rapidly exploiting these trends for their benefit. The current pandemic is no exception. Unit 42 has previously reported on how [cybercriminals have preyed on consumers during COVID-19](https://unit42.paloaltonetworks.com/how-cybercriminals-prey-on-the-covid-19-pandemic/) and on [the use of COVID-19 themed phishing attacks impersonating brands like Pfizer and BioNTech](https://unit42.paloaltonetworks.com/covid-19-themed-phishing-attacks/). This article provides early warnings for the travel industry and global travelers by sharing information about various attack attempts targeting the travel industry.

At the beginning of the pandemic, when people all over the world scrambled to get protective supplies -- personal protective equipment, sanitizer and toilet paper -- threat actors tried to take advantage of supply issues by selling fake products. They also tried to trick people by purporting to be credible health organizations (such as the WHO) or pharmaceutical companies, all while the actual organizations and companies were trying to make sense of the virus and come up with metrics, protective measures and vaccines.

Although the pandemic is not over, as the world opens up borders and the vaccines slow down the spread of the virus, people who have been cooped up at home are eager to travel. Threat actors are taking advantage of this trend by using travel as a theme for phishing people and stealing data -- account credentials, financial information and so on -- subsequently selling this data in underground markets.

Here, we first show that there has been a substantial increase in the registration of travel-related phishing URLs in 2021. Second, we provide two real-life examples demonstrating attackers abusing the travel theme, including the Dridex malware distribution and the abuse of Firebase in phishing campaigns. Third, we talk about how threat actors use various data that they steal. Finally, we conclude with a discussion of best practices for both individuals and organizations.

Please note that Palo Alto Networks [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) customers are protected from phishing attacks with various security services, including [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire).

## Increase in Travel-themed Phishing

To conduct social engineering, threat actors have always leveraged malicious domains and URLs impersonating known brands and websites familiar to end users. The content served on these malicious domains or URLs is crafted to mislead end users, since they look and feel very similar to brands that users know.

Alternatively, threat actors also send phishing emails to end users to trick them into either downloading malicious attachments or clicking on links that lead to malicious content -- website pages or attachments. Threat actors use themes that invoke a sense of urgency (such as outstanding invoices) or appeal to the end user emotionally (such as travel-themed emails sent as the world opens up).

### Increase in the Number of Travel-themed Phishing URLs

Unit 42 analyzed travel-themed phishing URLs created between October 2019 and August 2021. As seen in Figure 1 below, there is a gradual upward trend in the registration of phishing URLs starting early 2021, with a significant increase in June 2021. Though the new phishing URLs did not continue to be registered at quite the frenzied rate we saw in June, throughout the summer, threat actors created new travel-themed phishing URLs at a much higher level than at any time in 2020.
![New travel-themed phishing URLs, shown in terms of the phishing URL creation date. Note the steep rise beginning in May 2021.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/09/word-image-37.png) Figure 1. Number of new travel-themed phishing URLs registered between October 2019 and August 2021.

Based on the new phishing URLs that Unit 42 observed, in addition to the use of bespoke/new domains for serving the phishing URLs, threat actors also leveraged URL shorteners such as bit.ly and bit.do, and services such as Firebase that are hosted on Google Cloud Storage. Firebase is backed by Google and supports developers of mobile or web applications. Firebase includes cloud storage that enables developers to store and serve user-generated content. As Firebase leverages Google Cloud Storage, it is possible for phishing URLs to take advantage of it to bypass email protections based on Google's reputation.

Unit 42 observed that not all the phishing URLs that threat actors leveraged were used for directed attacks or campaigns; some of the URLs were used in malspam campaigns to host malicious content, such as Dridex.

### Use of Travel-themed Phishing URLs by Dridex

Dridex is mass-distribution malware that is typically sent through malspam. Dridex has been known as an information-stealing malware or banking trojan that targets Windows platforms and is distributed via malicious spam attachments impersonating legitimate companies.

The threat actor behind Dridex generally uses billing- or invoice-themed emails, a tactic used by most mass-distribution malware. The compromised or malicious URLs host the initial installer for Dridex to establish backdoor access. The backdoor access established by Dridex is later used to distribute followup malware, including ransomware, if the initial infection is not discovered.

The domains associated with the compromised URLs leveraged by Dridex are usually legitimate but compromised websites. For most Dridex campaigns, these URLs are used for a single day before the campaign moves on to a different URL.

Unit 42 researchers have observed two types of malspam pushing Dridex in the past few months: (1) a phishing email with an Excel spreadsheet attachment, and (2) a phishing email with a link to a message to download an Excel spreadsheet.
![Infection chain for phishing emails pushing Dridex using an Excel spreadsheet attachment: 1) Malicious spam with attached Excel file, 2) Enable macros in the Excel file, 3) Reach out to malicious URLs, 4) Download installer DLL for Dridex, 5) Dridex command and control, 6) 64-bit DLLs for Dridex.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/09/word-image-38.png) Figure 2. Infection chain for phishing emails with an Excel spreadsheet attachment. ![Infection chain for phishing emails linked to a message to download and Excel spreadsheet pushing Dridex: 1) Malicious spam with Dropbox link in the message text, 2) Download spreadsheet with macros from Dropbox, 3) Enable macros in the Excel file, 4) Reach out to malicious URLs, 5) Download installer DLL for Dridex, 6) Dridex C2, 7) 64-bit DLLs for Dridex.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/09/word-image-39.png) Figure 3. Infection chain for phishing emails linked to a message to download an Excel spreadsheet.

Unit 42 has published multiple articles over the past few years using the tag "[Dridex](https://unit42.paloaltonetworks.com/tag/dridex/)."

From the newly registered phishing URLs, Unit 42 observed that a couple of phishing URLs with travel-related keywords -- "airlines" and "vacation" -- were used by Dridex in 2021. These URLs are:

* animalairlines\[.\]org/wp-content/plugins/wordpress-seo/inc/options/tk2xzwhphujenf.php
* soleravacation\[.\]net/wp-content/plugins/mojo-marketplace-wp-plugin-is-broke/inc/cli/mxq6awnfhnmadd2.php

#### Technical Details About

**animalairlines\[.\]org/wp-content/plugins/wordpress-seo/inc/options/tk2xzwhphujenf.php**

In January 2021, there was a malspam campaign that comprised emails that used Dropbox links to call animalairlines\[.\]org/wp-content/plugins/wordpress-seo/inc/options/tk2xzwhphujenf.php and download the malware DLL to install Dridex.
![Example email associated with a malspam campaign that comprised emails that used Dropbox links to call travel-themed phishing URLs and download the malware DLL to install Dridex.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/09/word-image-40.png) Figure 4. Example email associated with the campaign.

The SHA256 values associated with some of the samples identified by Unit42 researchers are:

|------------------------------------------------------------------|------------------------|
| **Hash**                                                         | **Filename**           |
| 2741a353c6d7bc69bf43aef709ead2d6f452e895561943b01ad5359561506092 | Rep\_598531.xls         |
| 5134f99242ea705442aaf857d43c4e689cd117a64fe103353be7f8ec5fd165f4 | Name unknown           |
| 6846ae3db07fdc05aa310d157f9300bd7d26c33e5e81594dc89b70b47c73ee43 | Name unknown           |
| 80d50ab8fe6f880270a2d8c3646a2272efed3f7a68140afacb72317a2e0c42c7 | Note\_7706.xls          |
| b25edec6855cd5c3b74fa1a897d33978a227ccd039ac175c71521ec3655ebe10 | Information\_24837.xls  |
| f3c837323c135a7d7ed9d03f856c81463abb80174211117f4bda193a55f1b78e | Notification\_30123.xls |

A list of Dropbox URLs associated with this wave of malspam are:

* hxxps://www.dropbox\[.\]com/s/qmi112rc4ns75eb/Confidential\_123.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/pfs4wf7a8mzxxkf/Notification%20%23591501.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/dz2b5ypqvoy7tpa/Reports%2078497.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/azswbhh7gmxouk2/Rep%20%231018.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/myz2ytmvd08vfl4/Invoice%20%2392899.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/66j21yxz64fwfg2/Documentation%20644.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/81pphar6s4e93vz/Detailed%20079.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/yryqu9i368uib62/Report\_%23\_301.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/1ds4kb2limantm5/Notification\_836524.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/yo9cy2y1su23ga1/Rep%20%23621.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/zakw3n6nvxqoyav/Subconract%20415.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/7vgj2bvv3vnd8dj/Note%20%2383008.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/l1bl35aybsvu8wl/Notification\_71823.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/myoyguvb1qhrwsk/Reports\_6633.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/4xecieojug0y28l/Information%20714353.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/glyefet40tkve8u/Contract%2030964.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/6f1amba84r7sf4a/Inv%204529.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/8y95urd2as2eeu8/Inv%20%23147.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/9wj6fcxxw29sfcp/Contract\_724269.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/qu6npuiok79zpeo/Inv\_225.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/ckihhm4uaxfi5hs/Report\_18392.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/ryyogkwdvwof8rs/Scan%20108.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/5jgm0ktunwiby10/Subconract\_848.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/luee4b7upuo2kak/Rep%20%23226186.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/c6rqxbq9ydl2sd1/Reports%20%2348406.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/4jczljfya09ye2o/Notification\_30123.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/f62i6djdmb4qm6b/Subconract\_1541.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/cvrhnc9h6e9ny1y/Contract\_%23\_599848.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/5nz7l5ftiu48irm/Fax%20740.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/atagwpkwhmpmvi4/Detailed\_%23\_670.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/v0hmuvpunssgon3/Note%202365.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/9779leob93657a9/Invoice\_%23\_76493.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/agx2xx6bbpetdh7/Copy\_%23\_824.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/l3d6i2x6f2ui9pk/Notice%200118.xls?dl=1

Once Dropbox was provided Palo Alto Networks threat intelligence, it immediately disabled sharing of those links and disabled the associated account to prevent further threat actor activity.

The URL hxxp://go7wallet\[.\]com/app/plugins/cordova-plugin-statusbar/src/browser/HLn3obcR1vMJZNt.php was also contacted as part of the campaign.

#### Technical Details About

**soleravacation\[.\]net/wp-content/plugins/mojo-marketplace-wp-plugin-is-broke/inc/cli/mxq6awnfhnmadd2.php**

In February and March 2021, there was a malspam campaign that comprised emails with Excel attachments to call soleravacation\[.\]net/wp-content/plugins/mojo-marketplace-wp-plugin-is-broke/inc/cli/mxq6awnfhnmadd2.php and subsequently download the malware DLL to install Dridex.

The SHA256 values associated with some of the samples identified by Unit 42 researchers are:

|------------------------------------------------------------------|---------------------|
| **Hash**                                                         | **Filename**        |
| 0edda7d9dfd825e5e69c1ae55e26adf6e7ade746492f48bff0c0cbcf4c924b84 | Attach 05680.xlsm   |
| 4dc9b2f11546e5bf8fb9901809a0707ff1e23acdc52742b991ddff18ce03733c | Name unknown        |
| bc30505fbd196a16346fc37c84ff8db3491fadc7c1b25e35b92954d570699eac | Name unknown        |
| bcaac658e2d7b0a51112b76f75ff678082300a12225ae9226274dbddd94a270c | Invoice 689160.xlsm |
| c5c34cf419acecfbdb8c63fd603f11cbcf6ef84453bfe27a975f2295acb68be2 | Attach 689160.xlsm  |
| e7cef58dba5c455b29b55d4d670449a69708ef17ed2866732177ea3e9fdbb69b | Name unknown        |
| ff5b57033bb5373fdebfe5efc84adcdd0bdddad382fa753b9c08483742401407 | Name unknown        |

Of note for this particular campaign, the malicious spreadsheets try to connect to five or more URLs to retrieve Dridex, in addition to soleravacation\[.\]net/wp-content/plugins/mojo-marketplace-wp-plugin-is-broke/inc/cli/mxq6awnfhnmadd2.php.

### Abuse of Firebase by Threat Actors

Threat actors have targeted multiple organizations within the travel industry and have used Firebase to host phishing pages to either target employees working in the travel industry or customers. Some of the organizations that have been targeted by Firebase-hosted web applications include an online marketplace for vacation rentals, upscale hotel chains, resort management companies and airline companies such as Tui.

As mentioned above, Firebase is backed by Google and supports developers of mobile or web applications, allowing them to store content in Google Cloud Storage. Unit 42 observed attackers taking advantage of the inherent legitimacy of the Google Firebase domain to deceive targets and to bypass security filters that block domains and files that are known to be malicious. Once Unit 42 notified Google, it immediately removed and blocked these phishing URLs to prevent further threat actor activity.

A sample of phishing URLs hosted on Firebase include:

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------|
| **URL**                                                                                                                                                                                             | **Purpose**                                         |
| firebasestorage\[.\]googleapis\[.\]com/v0/b/owambe-4ce77.appspot.com/o/arsenaldozens/index%20copy%202.html?alt=media%26token=bbb56e5d-96d2-4da7-a82f-e0bfed8d24c3%26email=creader@palaceresorts.com | Targeting employees working in the travel industry. |
| ehdewbml\[.\]firebaseapp\[.\]com/01iofurjdor.html#iuser=corp@tui.ru                                                                                                                                 | Targeting employees working in the travel industry. |

## How Attackers Use the Data Gathered Through Phishing

Cybercriminals often want to monetize any "data" that they acquire through attacks, and data gathered about travelers or organizations operating in the travel sector is no different. We have observed that threat actors monetize data by selling stolen account credentials, stolen customer data or stolen payment information.

During the pandemic, Unit 42 researchers noticed the supply for travel-themed services and products in underground markets drastically decreased (see Figure 5), possibly due to the global travel restrictions. However, we expect that both supply and demand will increase as the world reopens for travel.
:chart: Figure 5. Travel-themed products and services listed in underground marketplaces, October 2019-March 2021. (Data for later months not available.)

### Stolen Account Credentials

There are two main reasons criminals are attracted by data sets containing stolen usernames, emails and passwords. First, they give criminals access to victims' mileage or hotel points, which can easily be resold for profit. Second, the credentials can easily be used for compromising and taking over victims' accounts on other platforms, if the same credentials were used. With all the potential financial gains from stolen login credentials, the strong demand in underground marketplaces encourages threat actors to actively acquire this data through social engineering, brute-forcing or exploiting vulnerable systems.

### Stolen Customer Data

Organizations in the travel industry have access to a wealth of data, including personally identifiable information (PII), payment information and the contact information of customers. In the recent [SITA passenger](https://techcrunch.com/2021/05/23/air-india-passenger-data-breach-reveals-sita-hack-worse-than-first-thought/?guccounter=1) service system attack, 4.5 million global data subjects were compromised. While researchers attributed the attack to APT41, it was observed that financially motivated criminals also showed interest in this data.

There are three possible ways cybercriminals can abuse this type of data.

1. **Identity theft**: Using stolen individual information collected from website A to create new accounts on website B. Because victims are not aware of these accounts on website B, they are less likely to be notified until later.
2. **Reconnaissance**: Using the information for reconnaissance and setting the stage for spear phishing attacks.
3. **Resale of data**: Data can easily be resold to other criminals, fraudsters or illicit marketing service providers for further abuse.

### Stolen Payment Information

Cybercriminals have been offering a "shadow travel agency" service for years. They reach out to individual travelers through various social media or instant messaging platforms such as Telegram, providing flight bookings, hotel reservations, car rentals, car rides and sightseeing tours with heavily discounted prices. While travelers transfer clean money to the "shadow travel agency," the "shadow travel agency" pays the actual service providers such as hotels or airlines with stolen payment information. Due to the time gap in payment processing, service providers only realize they have been defrauded when they see the disputed card transactions or chargebacks weeks or months later.

There are three groups of victims in this scenario. The first victim group is the payment information owners and stolen credit card holders. The second victim group is the travelers who were unknowingly a part of the money laundering process, giving cybercriminals opportunities to cash out the stolen payment information they previously collected. Travel industry organizations are considered the third victim group; they are the most impacted in this scheme. Not only did they fail to profit from the products and services they provided, but they also had to cover the costs and chargeback penalties, as well as addressing the reputational impacts of the crime.
![How threat actors abuse stolen payment information, illustrated in a flowchart. Criminals collected stolen payment information through phishing or malware, and later monetize the data via their "shadow travel agency." This affects three groups of victims. Victim 1: Stolen payment information owners whose data were abused by criminals. Victim 2: Travelers who paid "shadow travel agency" - trips may be disrupted with no refund. Victim 3: Travel companies that provided actual services but paid fines and refunds due to fraud disputes filed by Victim 1.](https://unit42.paloaltonetworks.com/wp-content/uploads/2021/09/word-image-41.png) Figure 6. Abuse of stolen payment information by threat actors.

## Conclusion

The travel industry and international travelers have been long-term targets for cybercriminals, suffering financial and reputational damage. Threat actors not only sell fabricated information but also stolen information that they gather through phishing attacks. During the pandemic, we noticed that travel-themed products and services offered by cybercriminals in underground marketplaces decreased significantly, possibly due to low demand. However, as travel resumes, we expect travelers and the travel industry to be targeted again due to the high profitability associated with this data. Therefore, it is important to be aware of phishing campaigns.

Best practices to protect yourself and your organization from phishing attacks include:

**For individuals:**

* Exercise caution when clicking on any links or attachments contained in suspicious emails, especially those relating to one's account settings or personal information, or otherwise trying to convey a sense of urgency.
* Verify the sender's address for any suspicious emails in your inbox.
* Double-check the URL and security certificate of each website before inputting your login credentials.
* Report suspected phishing attempts.

**For organizations:**

* Implement security awareness training to improve employees' ability to identify fraudulent emails.
* Regularly back up your organization's data as a defense against ransomware attacks initiated via phishing emails.
* Enforce multi-factor authentication on all business-related logins as an added layer of security.

Palo Alto Networks customers are protected by:

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering): Detects unknown, newly malicious URLs in milliseconds instead of minutes, preventing successful attacks.
* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire): All known samples are identified as malware.
* [AutoFocus](https://www.paloaltonetworks.com/cortex/autofocus): Tracking related activity using the Dridex tag.

### Additional Resources

* [Worldwide Phishing Attacks Ramped Up at the Peak of Working From Home](https://unit42.paloaltonetworks.com/phishing-attacks/)
* [Fake Websites Used in COVID-19 Themed Phishing Attacks, Impersonating Brands Like Pfizer and BioNTech](https://unit42.paloaltonetworks.com/covid-19-themed-phishing-attacks/)
* [COVID-19: The Cybercrime Gold Rush of 2020](https://www.paloaltonetworks.com/blog/2020/07/unit-42-cybercrime-gold-rush/)
* [Studying How Cybercriminals Prey on the COVID-19 Pandemic](https://unit42.paloaltonetworks.com/how-cybercriminals-prey-on-the-covid-19-pandemic/)

### Acknowledgements

Special thanks to Bradley Duncan, Lucas Hu, Zhanhao Chen and Bennett Woo for all the insightful data and experience sharing.

### Indicators of Compromise

#### URLs

* soleravacation\[.\]net/wp-content/plugins/mojo-marketplace-wp-plugin-is-broke/inc/cli/mxq6awnfhnmadd2.php
* animalairlines\[.\]org/wp-content/plugins/wordpress-seo/inc/options/tk2xzwhphujenf.php
* hxxp://go7wallet.com/app/plugins/cordova-plugin-statusbar/src/browser/HLn3obcR1vMJZNt.php
* hxxps://www.dropbox\[.\]com/s/qmi112rc4ns75eb/Confidential\_123.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/pfs4wf7a8mzxxkf/Notification%20%23591501.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/dz2b5ypqvoy7tpa/Reports%2078497.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/azswbhh7gmxouk2/Rep%20%231018.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/myz2ytmvd08vfl4/Invoice%20%2392899.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/66j21yxz64fwfg2/Documentation%20644.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/81pphar6s4e93vz/Detailed%20079.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/yryqu9i368uib62/Report\_%23\_301.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/1ds4kb2limantm5/Notification\_836524.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/yo9cy2y1su23ga1/Rep%20%23621.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/zakw3n6nvxqoyav/Subconract%20415.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/7vgj2bvv3vnd8dj/Note%20%2383008.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/l1bl35aybsvu8wl/Notification\_71823.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/myoyguvb1qhrwsk/Reports\_6633.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/4xecieojug0y28l/Information%20714353.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/glyefet40tkve8u/Contract%2030964.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/6f1amba84r7sf4a/Inv%204529.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/8y95urd2as2eeu8/Inv%20%23147.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/9wj6fcxxw29sfcp/Contract\_724269.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/qu6npuiok79zpeo/Inv\_225.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/ckihhm4uaxfi5hs/Report\_18392.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/ryyogkwdvwof8rs/Scan%20108.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/5jgm0ktunwiby10/Subconract\_848.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/luee4b7upuo2kak/Rep%20%23226186.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/c6rqxbq9ydl2sd1/Reports%20%2348406.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/4jczljfya09ye2o/Notification\_30123.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/f62i6djdmb4qm6b/Subconract\_1541.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/cvrhnc9h6e9ny1y/Contract\_%23\_599848.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/5nz7l5ftiu48irm/Fax%20740.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/atagwpkwhmpmvi4/Detailed\_%23\_670.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/v0hmuvpunssgon3/Note%202365.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/9779leob93657a9/Invoice\_%23\_76493.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/agx2xx6bbpetdh7/Copy\_%23\_824.xls?dl=1
* hxxps://www.dropbox\[.\]com/s/l3d6i2x6f2ui9pk/Notice%200118.xls?dl=1

#### SHA256 and Filenames

|------------------------------------------------------------------|------------------------|
| **Hash**                                                         | **Filename**           |
| 2741a353c6d7bc69bf43aef709ead2d6f452e895561943b01ad5359561506092 | Rep\_598531.xls         |
| 5134f99242ea705442aaf857d43c4e689cd117a64fe103353be7f8ec5fd165f4 | Name unknown           |
| 6846ae3db07fdc05aa310d157f9300bd7d26c33e5e81594dc89b70b47c73ee43 | Name unknown           |
| 80d50ab8fe6f880270a2d8c3646a2272efed3f7a68140afacb72317a2e0c42c7 | Note\_7706.xls          |
| b25edec6855cd5c3b74fa1a897d33978a227ccd039ac175c71521ec3655ebe10 | Information\_24837.xls  |
| f3c837323c135a7d7ed9d03f856c81463abb80174211117f4bda193a55f1b78e | Notification\_30123.xls |
| 0edda7d9dfd825e5e69c1ae55e26adf6e7ade746492f48bff0c0cbcf4c924b84 | Attach 05680.xlsm      |
| 4dc9b2f11546e5bf8fb9901809a0707ff1e23acdc52742b991ddff18ce03733c | Name unknown           |
| bc30505fbd196a16346fc37c84ff8db3491fadc7c1b25e35b92954d570699eac | Name unknown           |
| bcaac658e2d7b0a51112b76f75ff678082300a12225ae9226274dbddd94a270c | Invoice 689160.xlsm    |
| c5c34cf419acecfbdb8c63fd603f11cbcf6ef84453bfe27a975f2295acb68be2 | Attach 689160.xlsm     |

Back to top

### Tags

* [COVID](https://unit42.paloaltonetworks.com/tag/covid/ "COVID")
* [Dridex](https://unit42.paloaltonetworks.com/tag/dridex/ "Dridex")
* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")
* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [Tourism](https://unit42.paloaltonetworks.com/tag/tourism/ "tourism")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: PhishingJS: A Deep Learning Model for JavaScript-Based Phishing Detection](https://unit42.paloaltonetworks.com/javascript-based-phishing/ "PhishingJS: A Deep Learning Model for JavaScript-Based Phishing Detection")

### Table of Contents

* 

### Related Articles

* [Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "article - table of contents")
* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")
* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")

## Related Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
