Threat reportMalwareTL-2026-1010

TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector

highACTIVE

TONResolver Remote Access Trojan (TL-2026-1010), also tracked as TONResolver, is a high-severity malware campaign, first published 2026-06-30. It has no confirmed attribution, affects Microsoft Windows, maps to 47 MITRE ATT&CK techniques (T1001, T1003, T1005), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
47MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-1010

Threat ID
TL-2026-1010
Also known as
TONResolver, Blockchain C2 RAT, TON-Dead-Drop-RAT, Booking.com Phishing Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
ESPIONAGE
Target sectors
hospitality, tourism, travel, accommodation, hotel-chains, booking-platforms, payment-processing
Target regions
japan, East Asia, Southeast Asia
Detection rules
9
Indicators of compromise
20

Malware and tooling in TONResolver Remote Access Trojan

Malware and tooling: TONResolver

How TONResolver Remote Access Trojan works

TONResolver is an active Remote Access Trojan (RAT) targeting Japanese hospitality and tourism businesses since late May 2026. The malware leverages TON blockchain smart contracts as a dead-drop resolver for command-and-control infrastructure, enabling attackers to switch C2 domains without recompiling the malware. Delivers via spear-phishing emails impersonating Booking.com with malicious .LNK files, exfiltrates system information, browser credentials, and payment data.

TONResolver represents a sophisticated, multi-stage RAT campaign demonstrating innovative abuse of blockchain technology to maintain resilient and decentralized command-and-control infrastructure. The attack chain begins with spear-phishing emails targeting Booking.com partner hotel management across Japan, crafted to appear as urgent guest complaints or booking alerts requiring immediate action. These emails contain Windows shortcut (.LNK) files that exploit Windows Explorer's icon rendering functionality to execute arbitrary PowerShell or batch scripts without triggering Windows Defender SmartScreen due to file type obfuscation. Once executed, the RAT establishes persistence through multiple mechanisms: registry run keys, scheduled tasks, Windows services, and startup folder entries, ensuring resilience across reboots. The malware communicates with TON blockchain smart contracts deployed on the TON network, where encoded C2 domain information is stored as immutable contract data (dead-drop resolver pattern). This design allows threat actors to pivot C2 infrastructure without requiring malware recompilation or re-distribution, significantly extending campaign longevity and evading traditional domain/IP-based takedown operations. The malware performs extensive system enumeration (hostname, Windows version, AD domain membership, user accounts, installed software), harvests stored credentials from Chrome and Microsoft Edge browsers by directly accessing LevelDB databases in the user profile directory, enumerates running processes to identify security software, and establishes remote interactive shell access via reverse TCP or HTTP tunneling. Post-compromise, attackers move laterally using harvested credentials and exploit privilege escalation vulnerabilities (CVE-2023-21674 variant exploitation techniques observed). The targeting of Japan's hospitality and tourism sector indicates economic espionage motivation, with secondary financial theft objectives: hotel booking data, guest payment card information, staff credentials for lateral network movement, and customer records from reservation systems. The use of blockchain-based C2 infrastructure demonstrates sophisticated adversary OpSec and knowledge of emerging evasion techniques, positioning this threat at the intersection of financial cybercrime and state-sponsored espionage. Campaign infrastructure analysis reveals registrations across multiple bullet-proof hosting providers with weak KYC, primarily Eastern European and Russian-affiliated providers, suggesting state-nexus operations or well-resourced criminal syndicate.

MITRE ATT&CK techniques used in TL-2026-1010

command-and-control

T1001 Data Obfuscation

Credential Access

T1003 OS Credential Dumping; T1187 Forced Authentication; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data

Command and Control

T1008 Fallback Channels; T1071 Application Layer Protocol; T1090 Proxy; T1092 Communication Through Removable Media; T1568 Dynamic Resolution; T1571 Non-Standard Port; T1573 Encrypted Channel

Discovery

T1012 Query Registry; T1057 Process Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery

Lateral Movement

T1021 Remote Services; T1550 Use Alternate Authentication Material; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1204 User Execution

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1134 Access Token Manipulation; T1548 Abuse Elevation Control Mechanism

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in TONResolver Remote Access Trojan

  • Microsoft — Windows
    Vulnerable versions: Windows 7 SP1; Windows 8.1; Windows 10 (1909 - 22H2); Windows 11 (21H2 - 23H2); Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022
  • Google — Chrome
    Vulnerable versions: All versions (credential theft via LevelDB access)
  • Microsoft — Microsoft Edge
    Vulnerable versions: All versions (credential theft via LevelDB access)
  • Booking.com — Partner Portal / Extranet
    Vulnerable versions: All versions (targeted via spear-phishing)
  • Hotel Management Systems — PMS (Property Management System)
    Vulnerable versions: Common PMS platforms (Micros, Agilysys, etc.) when compromised via endpoint

Remediation for TONResolver Remote Access Trojan

Immediate actions

  • Block all known TONResolver C2 domains, IPs, and ASNs at perimeter firewalls and DNS filters
  • Isolate and reimagine any systems infected with TONResolver (hash-based detection via MD5/SHA-256)
  • Scan browser profile directories for evidence of LevelDB credential database access and file timestamps
  • Review email gateway logs for inbound messages with .LNK attachments and impersonated Booking.com sender domains
  • Revoke all cached domain credentials and multi-factor authentication tokens for affected user accounts
  • Block TON blockchain network traffic (port 30303 TCP/UDP) and TON RPC endpoints at egress firewalls
  • Implement DNS sinkhole rules for TON smart contract query domains (*.ton, etc.)

Workarounds

  • Disable .LNK file execution from email attachments via email gateway attachment blocking rules
  • Restrict user-level file downloads via AppLocker and enforce read-only permissions on Desktop/Downloads
  • Disable PowerShell execution policy override via Group Policy (DisableScriptBlockLogging = false for auditing)
  • Block TON protocol resolution and blockchain RPC traffic at the firewall (port 30303, 443/8443 for RPC)

Longer-term hardening

  • Deploy advanced EDR with behavioral detection for .LNK file execution and child process spawning from Windows Explorer
  • Implement browser credential storage isolation via Windows Data Protection API (DPAPI) hardening
  • Deploy application allowlisting (AppLocker/WDAC) to restrict PowerShell/cmd.exe execution from user-writable directories
  • Enforce Windows Defender Device Guard / Hypervisor-Protected Code Integrity (HVCI) on high-value systems
  • Implement Host-Based Firewall rules to restrict scheduled task and Windows service creation by non-admin processes
  • Deploy network segmentation to isolate booking/reservation systems from general user workstations
  • Enable and centralize Windows Security Event logging for process creation (4688), file access, and registry modifications

Weaknesses (CWE) in TONResolver Remote Access Trojan

CWE-1104, CWE-426, CWE-427, CWE-434, CWE-506

Timeline of TONResolver Remote Access Trojan

  • TONResolver phishing campaign begins targeting Japanese hospitality sector; initial reconnaissance and email list preparation by threat actors
  • First wave of spear-phishing emails sent to Booking.com partner hotels in Japan impersonating guest complaints and booking alerts
  • First confirmed infections of TONResolver RAT on Booking.com partner hotel systems in Nagasaki, Kyoto, and Tokyo prefectures
  • Compromised systems used for lateral movement; credential harvesting from browsers escalates compromise to additional hotel network systems and PMS platforms
  • Campaign expands with additional phishing waves; TONResolver variants deployed across 50+ hospitality organizations in Japan
  • Security researchers at SentinelOne identify blockchain-based C2 infrastructure using TON smart contracts; reverse engineering reveals sophisticated dead-drop resolver mechanism
  • Initial security analysis and threat report published on blockchain-based C2 techniques; IOC sharing begins among cybersecurity vendors
  • JPCERT/CC and cybersecurity vendors issue formal threat alert for Japanese hospitality sector; hotel associations advised of active compromise campaign
  • Trend Micro publishes detailed technical analysis of TONResolver; detection rules released for SPL, KQL, and Sigma
  • Malwarebytes Labs publishes comprehensive deep-dive analysis of RAT capabilities, C2 infrastructure, and indicators of compromise
  • Japanese law enforcement and METI (Ministry of Economy, Trade and Industry) issue incident response guidance; request for victim organizations to report compromises
  • Comprehensive threat report on TONResolver published by cybersecurity research community; campaign documented as ongoing with active C2 infrastructure and continued targeting

Sources cited for TONResolver Remote Access Trojan

Detection coverage for TL-2026-1010

As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1010 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats