# TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector

> TONResolver is an active Remote Access Trojan (RAT) targeting Japanese hospitality and tourism businesses since late May 2026. The malware leverages TON blockchain smart contracts as a dead-drop resolver for command-and-control infrastructure, enabling attackers to switch C2 domains without recompiling the malware. Delivers via spear-phishing emails impersonating Booking.com with malicious .LNK files, exfiltrates system information, browser credentials, and payment data.

- **Published:** 2026-06-30T00:00:00Z
- **Last reviewed:** 2026-06-30T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1010
- **ID:** TL-2026-1010
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

TONResolver represents a sophisticated, multi-stage RAT campaign demonstrating innovative abuse of blockchain technology to maintain resilient and decentralized command-and-control infrastructure. The attack chain begins with spear-phishing emails targeting Booking.com partner hotel management across Japan, crafted to appear as urgent guest complaints or booking alerts requiring immediate action. These emails contain Windows shortcut (.LNK) files that exploit Windows Explorer's icon rendering functionality to execute arbitrary PowerShell or batch scripts without triggering Windows Defender SmartScreen due to file type obfuscation. Once executed, the RAT establishes persistence through multiple mechanisms: registry run keys, scheduled tasks, Windows services, and startup folder entries, ensuring resilience across reboots. The malware communicates with TON blockchain smart contracts deployed on the TON network, where encoded C2 domain information is stored as immutable contract data (dead-drop resolver pattern). This design allows threat actors to pivot C2 infrastructure without requiring malware recompilation or re-distribution, significantly extending campaign longevity and evading traditional domain/IP-based takedown operations. The malware performs extensive system enumeration (hostname, Windows version, AD domain membership, user accounts, installed software), harvests stored credentials from Chrome and Microsoft Edge browsers by directly accessing LevelDB databases in the user profile directory, enumerates running processes to identify security software, and establishes remote interactive shell access via reverse TCP or HTTP tunneling. Post-compromise, attackers move laterally using harvested credentials and exploit privilege escalation vulnerabilities (CVE-2023-21674 variant exploitation techniques observed). The targeting of Japan's hospitality and tourism sector indicates economic espionage motivation, with secondary financial theft objectives: hotel booking data, guest payment card information, staff credentials for lateral network movement, and customer records from reservation systems. The use of blockchain-based C2 infrastructure demonstrates sophisticated adversary OpSec and knowledge of emerging evasion techniques, positioning this threat at the intersection of financial cybercrime and state-sponsored espionage. Campaign infrastructure analysis reveals registrations across multiple bullet-proof hosting providers with weak KYC, primarily Eastern European and Russian-affiliated providers, suggesting state-nexus operations or well-resourced criminal syndicate.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1583 Acquire Infrastructure
- T1586 Compromise Accounts
- T1588 Obtain Capabilities
- T1585 Establish Accounts
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1047 Windows Management Instrumentation
- T1547 Boot or Logon Autostart Execution
- T1053 Scheduled Task/Job
- T1543 Create or Modify System Process
- T1548 Abuse Elevation Control Mechanism
- T1134 Access Token Manipulation
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1685 Disable or Modify Tools
- T1497 Virtualization/Sandbox Evasion
- T1070 Indicator Removal
- T1555 Credentials from Password Stores
- T1003 OS Credential Dumping
- T1187 Forced Authentication
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1087 Account Discovery
- T1518 Software Discovery
- T1012 Query Registry
- T1069 Permission Groups Discovery
- T1057 Process Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1550 Use Alternate Authentication Material
- T1005 Data from Local System
- T1056 Input Capture
- T1113 Screen Capture
- T1115 Clipboard Data
- T1071 Application Layer Protocol
- T1092 Communication Through Removable Media
- T1008 Fallback Channels
- T1568 Dynamic Resolution

## Sources

- [TONResolver Malware Uses TON Smart Contracts as Dead Drop Resolver for C2 Switching](https://cybersecuritynews.com/tonresolver-malware-uses-ton-smart-contracts/)
- [Threat Alert: Japanese Hospitality Sector Under Targeted Attack](https://cybersecuritynews.com/japanese-hospitality-threat/)
- [Windows .LNK File Exploitation Techniques and Detection](https://www.microsoft.com/en-us/security/blog/2026/05/30/lnk-exploitation/)
- [Blockchain-Based Command and Control Infrastructure in Malware](https://www.sentinelone.com/blog/blockchain-c2-infrastructure/)
- [TON Network Security Analysis: Smart Contract Exploitation Vectors](https://ton.org/analysis/malware-patterns)
- [JPCERT/CC: Alert on Japanese Hospitality Sector Targeting](https://www.jpcert.or.jp/english/at/2026/at260023.html)
- [Malwarebytes Labs: TONResolver Malware Deep Dive](https://labs.malwarebytes.com/tonresolver-analysis/)
- [Trend Micro: Blockchain-Based RAT Infrastructure Detection](https://www.trendmicro.com/vinfo/tonresolver-blockchain-rat/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1010
