Threat reportMalwareTL-2026-3093

Hotel-Targeted Fake Guest Complaint Phishing Delivers EtherRAT and TONResolver with Blockchain Dead-Drop C2

highACTIVE

Hotel-Targeted Fake Guest Complaint Phishing Delivers (TL-2026-3093) is a high-severity malware campaign, first published 2026-10-09 and last reviewed 2026-10-10. It has no confirmed attribution, affects Microsoft Windows (hotel front desk, reservations and guest relations, maps to 22 MITRE ATT&CK techniques (T1003.001, T1005, T1027), and is covered by 9 detection rules and 33 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
22MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
33Indicators of compromise

Key facts for TL-2026-3093

Threat ID
TL-2026-3093
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
hospitality, travel
Target regions
Global, japan
Detection rules
9
Indicators of compromise
33
Updates
2026-10-10 · 2 updates · revalidated 2× · latest source

Malware and tooling in Hotel-Targeted Fake Guest Complaint Phishing Delivers

Malware and tooling: EtherRAT, TrojanSpy.JS.TONRESOLVER.A

How Hotel-Targeted Fake Guest Complaint Phishing Delivers works

Phishing emails impersonating guest complaints, negative reviews and legal threats target hotel front desk, reservations and guest relations staff, delivering archives with LNK files disguised as images. The LNK installs a Node.js runtime and the EtherRAT or TONResolver backdoor, which resolve their C2 domains from Ethereum and TON smart contracts.

Cofense Intelligence (report dated 2026-10-07, researcher Kahng An) describes a campaign in which hotel staff receive emails that vary from simple accommodation questions to legal threats, posing as guest complaints or negative reviews. Cofense assesses with moderate confidence that generative AI is used to vary the email text. Links in the emails lead to archives containing a Windows shortcut (LNK) disguised as a JPG image, plus dummy MP4 files of varying size that give each archive a different hash and defeat hash-based detection.

Opening the shortcut downloads a Node.js runtime and installs either EtherRAT or TONResolver. Trend Micro's analysis of the TONResolver branch (campaign observed in May 2026 against Japanese Booking.com partner accommodation facilities) shows the LNK embedding a PowerShell command that uses System.Numerics.BigInteger arithmetic to decode a domain, then uses Invoke-WebRequest to fetch a PS1 script. The script creates %USERPROFILE%\AppData\Local\Nodejs\, downloads node-v24.13.0-win-x64.zip from nodejs.org, saves a JavaScript payload (detected as TrojanSpy.JS.TONRESOLVER.A) and runs it with node.exe {filename}.js {DomainName}. The payload sets the HKCU Run key for persistence.

Both families use blockchain dead-drop resolution instead of hardcoded C2. EtherRAT issues eth_call requests to an Ethereum smart contract through public JSON-RPC services; TONResolver queries the TON API (tonapi.io get_domain method) for a contract. The returned hexadecimal data is decoded and lightly unmasked to recover the current C2 address. Operators rotate C2 by submitting a small blockchain transaction rather than registering new domains, which gives takedown resilience and makes traffic resemble legitimate wallet or API activity.

TONResolver communicates over a WebSocket channel using ECDH (secp256k1) key exchange, HKDF-SHA256 key derivation and AES-256-CBC, with a 20-second ping/pong keepalive. Message types 0-8 cover keepalives, key exchange, endpoint information (username, hostname, OS, CPU, memory, MAC address), arbitrary JavaScript execution, result return, file retrieval/execution and PowerShell execution. Trend Micro observed second-stage malware dropped in the user Temp folder that accessed Chrome and Edge data directories, interacted with lsass.exe and read browser SQLite databases (passwords, cookies, history, autofill), indicating credential theft. The TON contract C2 domain history is: amanohuguta.cfd (2026-02-07), hsaertyuoang34.sbs (2026-02-09), zloapobikahy23.bond (2026-02-20), tonajukbhuakpo2.shop (2026-06-02).

Attribution: no named actor. Cofense assesses with moderate confidence that this continues earlier Booking.com-themed phishing that delivered PureRAT or NetSupport Manager via ClickFix pages, while noting that shared tooling used by separate groups could also explain the similarities. Severity is the analyst's judgment, not a source-stated rating. Note: an unrelated EtherRAT campaign reported by Sysdig (React2Shell exploitation, Linux persistence, linked to DPRK Contagious Interview overlap) uses a different Ethereum contract and is not evidenced as linked to this hotel campaign.

MITRE ATT&CK techniques used in TL-2026-3093

Credential Access

T1003.001 LSASS Memory; T1555.003 Credentials from Web Browsers

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036.008 Masquerade File Type; T1140 Deobfuscate/Decode Files or Information; T1562.001 Impair Defenses

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.001 PowerShell; T1059.007 JavaScript; T1204.001 User Execution; T1204.002 Malicious File

Command and Control

T1071.001 Application Layer Protocol; T1102.001 Dead Drop Resolver; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution; T1571 Non-Standard Port; T1573.001 Symmetric Cryptography

Discovery

T1082 System Information Discovery

Persistence

T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains

Affected products and versions in Hotel-Targeted Fake Guest Complaint Phishing Delivers

  • Microsoft — Windows (hotel front desk, reservations and guest relations endpoints)
    Vulnerable versions: Windows endpoints where users can open LNK files from downloaded archives

Remediation for Hotel-Targeted Fake Guest Complaint Phishing Delivers

Immediate actions

  • Block the listed C2 domains and Azure cloudapp/trycloudflare hostnames at DNS and proxy
  • Hunt for node.exe running from %USERPROFILE%\AppData\Local\Nodejs\ and for HKCU Run entries launching node.exe with a .js file
  • Alert on non-developer endpoints making eth_call JSON-RPC requests or requests to tonapi.io get_domain
  • Isolate affected hosts and reset browser-stored and domain credentials for users who opened the shortcut

Workarounds

  • Block public blockchain RPC and TON API endpoints for endpoints that have no business need for them
  • Block download of archives from newly registered .cfd, .sbs, .bond, .shop and .lol domains

Longer-term hardening

  • Block or detonate LNK files inside downloaded archives and show file extensions to users
  • Restrict execution of node.exe and PowerShell Invoke-WebRequest on front-desk and reservations endpoints (application control)
  • Train hotel guest-relations and reservations staff on fake complaint and review-request lures
  • Do not rely on file hashes for archives; detect on behavior (LNK to PowerShell to Node.js chain)

Timeline of Hotel-Targeted Fake Guest Complaint Phishing Delivers

  • TON contract updated to resolve C2 domain amanohuguta.cfd (Trend Micro).
  • TON contract rotated C2 to hsaertyuoang34.sbs.
  • TON contract rotated C2 to zloapobikahy23.bond.
  • Microsoft reports the photo-ZIP hospitality campaign delivering a Node.js implant has been active since April 2026 (month-level date).
  • In May 2026 (day approximate), phishing impersonating Booking.com guest complaints and review requests was observed targeting Japanese accommodation facilities, delivering TONResolver via LNK-in-ZIP.
  • Start of the observed TONResolver phishing activity against Booking.com partner hotels in Japan (activity window 2026-05-17 to 2026-06-08, per Trend Micro).
  • TON contract rotated C2 to tonajukbhuakpo2.shop; Cloudflare nameservers for the domains changed from galilea/moura to brianna/roan around June.
  • Latest observed TONResolver activity in the Japanese hotel campaign per Trend Micro.
  • SOC Prime publishes analysis of Booking.com-themed hotel phishing delivering TonRAT via Node.js (LE3f0MRT.ps1, zloapobikahy23.bond).
  • Microsoft publishes analysis of the photo-ZIP hospitality campaign: RunOnce persistence refreshing the executable in a loop, Defender exclusions for temporary executables, and delivery via Calendly/SendGrid, share.google.com open redirects, Cloudflare-hosted .cfd domains and Gmail thread hijacking.
  • Trend Micro publishes its TONResolver RAT report on TON blockchain abuse targeting Japan's hotel industry.
  • Cofense Intelligence (Kahng An) publishes research on fake guest complaint phishing delivering EtherRAT and TONResolver to hotels, with Ethereum and TON contract IOCs.
  • Cybersecurity News reports the campaign; hunt created for this threat.

Update history for TL-2026-3093

Sources cited for Hotel-Targeted Fake Guest Complaint Phishing Delivers

Detection coverage for TL-2026-3093

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3093 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
33 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-3093

3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats