Threat reportMalwareTL-2026-3093
Hotel-Targeted Fake Guest Complaint Phishing Delivers EtherRAT and TONResolver with Blockchain Dead-Drop C2
Hotel-Targeted Fake Guest Complaint Phishing Delivers (TL-2026-3093) is a high-severity malware campaign, first published 2026-10-09 and last reviewed 2026-10-10. It has no confirmed attribution, affects Microsoft Windows (hotel front desk, reservations and guest relations, maps to 22 MITRE ATT&CK techniques (T1003.001, T1005, T1027), and is covered by 9 detection rules and 33 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 33Indicators of compromise
Key facts for TL-2026-3093
- Threat ID
- TL-2026-3093
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- hospitality, travel
- Target regions
- Global, japan
- Detection rules
- 9
- Indicators of compromise
- 33
- Updates
- 2026-10-10 · 2 updates · revalidated 2× · latest source
Malware and tooling in Hotel-Targeted Fake Guest Complaint Phishing Delivers
Malware and tooling: EtherRAT, TrojanSpy.JS.TONRESOLVER.A
How Hotel-Targeted Fake Guest Complaint Phishing Delivers works
Phishing emails impersonating guest complaints, negative reviews and legal threats target hotel front desk, reservations and guest relations staff, delivering archives with LNK files disguised as images. The LNK installs a Node.js runtime and the EtherRAT or TONResolver backdoor, which resolve their C2 domains from Ethereum and TON smart contracts.
Cofense Intelligence (report dated 2026-10-07, researcher Kahng An) describes a campaign in which hotel staff receive emails that vary from simple accommodation questions to legal threats, posing as guest complaints or negative reviews. Cofense assesses with moderate confidence that generative AI is used to vary the email text. Links in the emails lead to archives containing a Windows shortcut (LNK) disguised as a JPG image, plus dummy MP4 files of varying size that give each archive a different hash and defeat hash-based detection.
Opening the shortcut downloads a Node.js runtime and installs either EtherRAT or TONResolver. Trend Micro's analysis of the TONResolver branch (campaign observed in May 2026 against Japanese Booking.com partner accommodation facilities) shows the LNK embedding a PowerShell command that uses System.Numerics.BigInteger arithmetic to decode a domain, then uses Invoke-WebRequest to fetch a PS1 script. The script creates %USERPROFILE%\AppData\Local\Nodejs\, downloads node-v24.13.0-win-x64.zip from nodejs.org, saves a JavaScript payload (detected as TrojanSpy.JS.TONRESOLVER.A) and runs it with node.exe {filename}.js {DomainName}. The payload sets the HKCU Run key for persistence.
Both families use blockchain dead-drop resolution instead of hardcoded C2. EtherRAT issues eth_call requests to an Ethereum smart contract through public JSON-RPC services; TONResolver queries the TON API (tonapi.io get_domain method) for a contract. The returned hexadecimal data is decoded and lightly unmasked to recover the current C2 address. Operators rotate C2 by submitting a small blockchain transaction rather than registering new domains, which gives takedown resilience and makes traffic resemble legitimate wallet or API activity.
TONResolver communicates over a WebSocket channel using ECDH (secp256k1) key exchange, HKDF-SHA256 key derivation and AES-256-CBC, with a 20-second ping/pong keepalive. Message types 0-8 cover keepalives, key exchange, endpoint information (username, hostname, OS, CPU, memory, MAC address), arbitrary JavaScript execution, result return, file retrieval/execution and PowerShell execution. Trend Micro observed second-stage malware dropped in the user Temp folder that accessed Chrome and Edge data directories, interacted with lsass.exe and read browser SQLite databases (passwords, cookies, history, autofill), indicating credential theft. The TON contract C2 domain history is: amanohuguta.cfd (2026-02-07), hsaertyuoang34.sbs (2026-02-09), zloapobikahy23.bond (2026-02-20), tonajukbhuakpo2.shop (2026-06-02).
Attribution: no named actor. Cofense assesses with moderate confidence that this continues earlier Booking.com-themed phishing that delivered PureRAT or NetSupport Manager via ClickFix pages, while noting that shared tooling used by separate groups could also explain the similarities. Severity is the analyst's judgment, not a source-stated rating. Note: an unrelated EtherRAT campaign reported by Sysdig (React2Shell exploitation, Linux persistence, linked to DPRK Contagious Interview overlap) uses a different Ethereum contract and is not evidenced as linked to this hotel campaign.
MITRE ATT&CK techniques used in TL-2026-3093
Credential Access
T1003.001 LSASS Memory; T1555.003 Credentials from Web Browsers
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036.008 Masquerade File Type; T1140 Deobfuscate/Decode Files or Information; T1562.001 Impair Defenses
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.001 PowerShell; T1059.007 JavaScript; T1204.001 User Execution; T1204.002 Malicious File
Command and Control
T1071.001 Application Layer Protocol; T1102.001 Dead Drop Resolver; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution; T1571 Non-Standard Port; T1573.001 Symmetric Cryptography
Discovery
T1082 System Information Discovery
Persistence
T1547.001 Registry Run Keys / Startup Folder
Initial Access
Resource Development
Affected products and versions in Hotel-Targeted Fake Guest Complaint Phishing Delivers
- Microsoft — Windows (hotel front desk, reservations and guest relations endpoints)
Vulnerable versions: Windows endpoints where users can open LNK files from downloaded archives
Remediation for Hotel-Targeted Fake Guest Complaint Phishing Delivers
Immediate actions
- Block the listed C2 domains and Azure cloudapp/trycloudflare hostnames at DNS and proxy
- Hunt for node.exe running from %USERPROFILE%\AppData\Local\Nodejs\ and for HKCU Run entries launching node.exe with a .js file
- Alert on non-developer endpoints making eth_call JSON-RPC requests or requests to tonapi.io get_domain
- Isolate affected hosts and reset browser-stored and domain credentials for users who opened the shortcut
Workarounds
- Block public blockchain RPC and TON API endpoints for endpoints that have no business need for them
- Block download of archives from newly registered .cfd, .sbs, .bond, .shop and .lol domains
Longer-term hardening
- Block or detonate LNK files inside downloaded archives and show file extensions to users
- Restrict execution of node.exe and PowerShell Invoke-WebRequest on front-desk and reservations endpoints (application control)
- Train hotel guest-relations and reservations staff on fake complaint and review-request lures
- Do not rely on file hashes for archives; detect on behavior (LNK to PowerShell to Node.js chain)
Timeline of Hotel-Targeted Fake Guest Complaint Phishing Delivers
- TON contract updated to resolve C2 domain amanohuguta.cfd (Trend Micro).
- TON contract rotated C2 to hsaertyuoang34.sbs.
- TON contract rotated C2 to zloapobikahy23.bond.
- Microsoft reports the photo-ZIP hospitality campaign delivering a Node.js implant has been active since April 2026 (month-level date).
- In May 2026 (day approximate), phishing impersonating Booking.com guest complaints and review requests was observed targeting Japanese accommodation facilities, delivering TONResolver via LNK-in-ZIP.
- Start of the observed TONResolver phishing activity against Booking.com partner hotels in Japan (activity window 2026-05-17 to 2026-06-08, per Trend Micro).
- TON contract rotated C2 to tonajukbhuakpo2.shop; Cloudflare nameservers for the domains changed from galilea/moura to brianna/roan around June.
- Latest observed TONResolver activity in the Japanese hotel campaign per Trend Micro.
- SOC Prime publishes analysis of Booking.com-themed hotel phishing delivering TonRAT via Node.js (LE3f0MRT.ps1, zloapobikahy23.bond).
- Microsoft publishes analysis of the photo-ZIP hospitality campaign: RunOnce persistence refreshing the executable in a loop, Defender exclusions for temporary executables, and delivery via Calendly/SendGrid, share.google.com open redirects, Cloudflare-hosted .cfd domains and Gmail thread hijacking.
- Trend Micro publishes its TONResolver RAT report on TON blockchain abuse targeting Japan's hotel industry.
- Cofense Intelligence (Kahng An) publishes research on fake guest complaint phishing delivering EtherRAT and TONResolver to hotels, with Ethereum and TON contract IOCs.
- Cybersecurity News reports the campaign; hunt created for this threat.
Update history for TL-2026-3093
- 2026-10-10 — Blockchain-Resolved C2 (EtherRAT, TONResolver) Targets Hotels via Fake Guest Complaint Emails with Malicious LNK Files: What changed Motivation UNKNOWN - FINANCIAL (Microsoft describes the activity as financially motivated). Severity, exploitability and status unchanged (HIGH / ACTIVE / ACTIVE). New indicators (0) No new IOCs; all contracts and C2 domains in
- 2026-10-10 — Fake Guest Complaint Phishing Targets Hotels to Deploy EtherRAT and TONResolver (Blockchain-Based RAT): What changed No severity, exploitability or status change; existing HIGH / ACTIVE values stand. New indicators (3) 3 new indicators: LE3f0MRT.ps1 stager filename (SOC Prime), the node.exe <random .js <domain execution pattern, and the BigIn
Sources cited for Hotel-Targeted Fake Guest Complaint Phishing Delivers
- Hackers Use Negative Hotel Reviews to Spread Malware That Hides C2 on Blockchain
- From Guest Complaints to Malware: Blockchain Abuse Targets Hotels (Cofense)
- Phishing Campaign Targets Japan's Hotels Using TONResolver RAT (Trend Micro)
- EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks (Sysdig, related but separate EtherRAT campaign)
- EtherRAT Techniques Bypass Security Via Ethereum Smart Contracts (Infosecurity Magazine)
- TONResolver RAT abuses TON blockchain to target Japan's hotels (ThreatCluster)
Detection coverage for TL-2026-3093
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3093 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-3093
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.