Threat reportMalwareTL-2026-1010
TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector
TONResolver Remote Access Trojan (TL-2026-1010), also tracked as TONResolver, is a high-severity malware campaign, first published 2026-06-30. It has no confirmed attribution, affects Microsoft Windows, maps to 47 MITRE ATT&CK techniques (T1001, T1003, T1005), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 47MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1010
- Threat ID
- TL-2026-1010
- Also known as
- TONResolver, Blockchain C2 RAT, TON-Dead-Drop-RAT, Booking.com Phishing Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- ESPIONAGE
- Target sectors
- hospitality, tourism, travel, accommodation, hotel-chains, booking-platforms, payment-processing
- Target regions
- japan, East Asia, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in TONResolver Remote Access Trojan
Malware and tooling: TONResolver
How TONResolver Remote Access Trojan works
TONResolver is an active Remote Access Trojan (RAT) targeting Japanese hospitality and tourism businesses since late May 2026. The malware leverages TON blockchain smart contracts as a dead-drop resolver for command-and-control infrastructure, enabling attackers to switch C2 domains without recompiling the malware. Delivers via spear-phishing emails impersonating Booking.com with malicious .LNK files, exfiltrates system information, browser credentials, and payment data.
TONResolver represents a sophisticated, multi-stage RAT campaign demonstrating innovative abuse of blockchain technology to maintain resilient and decentralized command-and-control infrastructure. The attack chain begins with spear-phishing emails targeting Booking.com partner hotel management across Japan, crafted to appear as urgent guest complaints or booking alerts requiring immediate action. These emails contain Windows shortcut (.LNK) files that exploit Windows Explorer's icon rendering functionality to execute arbitrary PowerShell or batch scripts without triggering Windows Defender SmartScreen due to file type obfuscation. Once executed, the RAT establishes persistence through multiple mechanisms: registry run keys, scheduled tasks, Windows services, and startup folder entries, ensuring resilience across reboots. The malware communicates with TON blockchain smart contracts deployed on the TON network, where encoded C2 domain information is stored as immutable contract data (dead-drop resolver pattern). This design allows threat actors to pivot C2 infrastructure without requiring malware recompilation or re-distribution, significantly extending campaign longevity and evading traditional domain/IP-based takedown operations. The malware performs extensive system enumeration (hostname, Windows version, AD domain membership, user accounts, installed software), harvests stored credentials from Chrome and Microsoft Edge browsers by directly accessing LevelDB databases in the user profile directory, enumerates running processes to identify security software, and establishes remote interactive shell access via reverse TCP or HTTP tunneling. Post-compromise, attackers move laterally using harvested credentials and exploit privilege escalation vulnerabilities (CVE-2023-21674 variant exploitation techniques observed). The targeting of Japan's hospitality and tourism sector indicates economic espionage motivation, with secondary financial theft objectives: hotel booking data, guest payment card information, staff credentials for lateral network movement, and customer records from reservation systems. The use of blockchain-based C2 infrastructure demonstrates sophisticated adversary OpSec and knowledge of emerging evasion techniques, positioning this threat at the intersection of financial cybercrime and state-sponsored espionage. Campaign infrastructure analysis reveals registrations across multiple bullet-proof hosting providers with weak KYC, primarily Eastern European and Russian-affiliated providers, suggesting state-nexus operations or well-resourced criminal syndicate.
MITRE ATT&CK techniques used in TL-2026-1010
command-and-control
Credential Access
T1003 OS Credential Dumping; T1187 Forced Authentication; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1090 Proxy; T1092 Communication Through Removable Media; T1568 Dynamic Resolution; T1571 Non-Standard Port; T1573 Encrypted Channel
Discovery
T1012 Query Registry; T1057 Process Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery
Lateral Movement
T1021 Remote Services; T1550 Use Alternate Authentication Material; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1204 User Execution
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Privilege Escalation
T1134 Access Token Manipulation; T1548 Abuse Elevation Control Mechanism
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1588 Obtain Capabilities
Reconnaissance
T1589 Gather Victim Identity Information
Impact
defense-impairment
Affected products and versions in TONResolver Remote Access Trojan
- Microsoft — Windows
Vulnerable versions: Windows 7 SP1; Windows 8.1; Windows 10 (1909 - 22H2); Windows 11 (21H2 - 23H2); Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022 - Google — Chrome
Vulnerable versions: All versions (credential theft via LevelDB access) - Microsoft — Microsoft Edge
Vulnerable versions: All versions (credential theft via LevelDB access) - Booking.com — Partner Portal / Extranet
Vulnerable versions: All versions (targeted via spear-phishing) - Hotel Management Systems — PMS (Property Management System)
Vulnerable versions: Common PMS platforms (Micros, Agilysys, etc.) when compromised via endpoint
Remediation for TONResolver Remote Access Trojan
Immediate actions
- Block all known TONResolver C2 domains, IPs, and ASNs at perimeter firewalls and DNS filters
- Isolate and reimagine any systems infected with TONResolver (hash-based detection via MD5/SHA-256)
- Scan browser profile directories for evidence of LevelDB credential database access and file timestamps
- Review email gateway logs for inbound messages with .LNK attachments and impersonated Booking.com sender domains
- Revoke all cached domain credentials and multi-factor authentication tokens for affected user accounts
- Block TON blockchain network traffic (port 30303 TCP/UDP) and TON RPC endpoints at egress firewalls
- Implement DNS sinkhole rules for TON smart contract query domains (*.ton, etc.)
Workarounds
- Disable .LNK file execution from email attachments via email gateway attachment blocking rules
- Restrict user-level file downloads via AppLocker and enforce read-only permissions on Desktop/Downloads
- Disable PowerShell execution policy override via Group Policy (DisableScriptBlockLogging = false for auditing)
- Block TON protocol resolution and blockchain RPC traffic at the firewall (port 30303, 443/8443 for RPC)
Longer-term hardening
- Deploy advanced EDR with behavioral detection for .LNK file execution and child process spawning from Windows Explorer
- Implement browser credential storage isolation via Windows Data Protection API (DPAPI) hardening
- Deploy application allowlisting (AppLocker/WDAC) to restrict PowerShell/cmd.exe execution from user-writable directories
- Enforce Windows Defender Device Guard / Hypervisor-Protected Code Integrity (HVCI) on high-value systems
- Implement Host-Based Firewall rules to restrict scheduled task and Windows service creation by non-admin processes
- Deploy network segmentation to isolate booking/reservation systems from general user workstations
- Enable and centralize Windows Security Event logging for process creation (4688), file access, and registry modifications
Weaknesses (CWE) in TONResolver Remote Access Trojan
Timeline of TONResolver Remote Access Trojan
- TONResolver phishing campaign begins targeting Japanese hospitality sector; initial reconnaissance and email list preparation by threat actors
- First wave of spear-phishing emails sent to Booking.com partner hotels in Japan impersonating guest complaints and booking alerts
- First confirmed infections of TONResolver RAT on Booking.com partner hotel systems in Nagasaki, Kyoto, and Tokyo prefectures
- Compromised systems used for lateral movement; credential harvesting from browsers escalates compromise to additional hotel network systems and PMS platforms
- Campaign expands with additional phishing waves; TONResolver variants deployed across 50+ hospitality organizations in Japan
- Security researchers at SentinelOne identify blockchain-based C2 infrastructure using TON smart contracts; reverse engineering reveals sophisticated dead-drop resolver mechanism
- Initial security analysis and threat report published on blockchain-based C2 techniques; IOC sharing begins among cybersecurity vendors
- JPCERT/CC and cybersecurity vendors issue formal threat alert for Japanese hospitality sector; hotel associations advised of active compromise campaign
- Trend Micro publishes detailed technical analysis of TONResolver; detection rules released for SPL, KQL, and Sigma
- Malwarebytes Labs publishes comprehensive deep-dive analysis of RAT capabilities, C2 infrastructure, and indicators of compromise
- Japanese law enforcement and METI (Ministry of Economy, Trade and Industry) issue incident response guidance; request for victim organizations to report compromises
- Comprehensive threat report on TONResolver published by cybersecurity research community; campaign documented as ongoing with active C2 infrastructure and continued targeting
Sources cited for TONResolver Remote Access Trojan
- TONResolver Malware Uses TON Smart Contracts as Dead Drop Resolver for C2 Switching
- Threat Alert: Japanese Hospitality Sector Under Targeted Attack
- Windows .LNK File Exploitation Techniques and Detection
- Blockchain-Based Command and Control Infrastructure in Malware
- TON Network Security Analysis: Smart Contract Exploitation Vectors
- JPCERT/CC: Alert on Japanese Hospitality Sector Targeting
- Malwarebytes Labs: TONResolver Malware Deep Dive
- Trend Micro: Blockchain-Based RAT Infrastructure Detection
Detection coverage for TL-2026-1010
As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1010 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.