Carnival Cruise Line booking emails served malware via lapsed promotional domain

A legitimate Carnival Cruise Line booking confirmation email, which passed all three standard email authentication checks, was routing real customers to malware through a promotional domain the company had allowed to expire. A third party re-registered the lapsed domain and connected it to a redirection network that fingerprinted visitors, serving a clean page to scanners and datacenter IPs while delivering malware installers and scareware to real browsers on home or mobile connections. The redirection layer, dubbed PseudoTDS, and the browser-hijacker payload, called PhantomJack, were previously documented by Trinity Cyber in November 2025, though that report traced infections to mistyped domains rather than authenticated marketing emails. The researcher who discovered this delivery path reported the issue, and Carnival re-acquired the lapsed domain on August 26th, 2026, after which the malicious vector was confirmed inactive. Public reputation and scanning services returned clean verdicts throughout the incident, as they consistently received the decoy parking page rather than the live malicious content.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in