# Hotel-Targeted Fake Guest Complaint Phishing Delivers EtherRAT and TONResolver with Blockchain Dead-Drop C2

> Phishing emails impersonating guest complaints, negative reviews and legal threats target hotel front desk, reservations and guest relations staff, delivering archives with LNK files disguised as images. The LNK installs a Node.js runtime and the EtherRAT or TONResolver backdoor, which resolve their C2 domains from Ethereum and TON smart contracts.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-10T09:33:29.396Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3093
- **ID:** TL-2026-3093
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 33 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Cofense Intelligence (report dated 2026-10-07, researcher Kahng An) describes a campaign in which hotel staff receive emails that vary from simple accommodation questions to legal threats, posing as guest complaints or negative reviews. Cofense assesses with moderate confidence that generative AI is used to vary the email text. Links in the emails lead to archives containing a Windows shortcut (LNK) disguised as a JPG image, plus dummy MP4 files of varying size that give each archive a different hash and defeat hash-based detection.

Opening the shortcut downloads a Node.js runtime and installs either EtherRAT or TONResolver. Trend Micro's analysis of the TONResolver branch (campaign observed in May 2026 against Japanese Booking.com partner accommodation facilities) shows the LNK embedding a PowerShell command that uses System.Numerics.BigInteger arithmetic to decode a domain, then uses Invoke-WebRequest to fetch a PS1 script. The script creates %USERPROFILE%\AppData\Local\Nodejs\, downloads node-v24.13.0-win-x64.zip from nodejs.org, saves a JavaScript payload (detected as TrojanSpy.JS.TONRESOLVER.A) and runs it with node.exe {filename}.js {DomainName}. The payload sets the HKCU Run key for persistence.

Both families use blockchain dead-drop resolution instead of hardcoded C2. EtherRAT issues eth_call requests to an Ethereum smart contract through public JSON-RPC services; TONResolver queries the TON API (tonapi.io get_domain method) for a contract. The returned hexadecimal data is decoded and lightly unmasked to recover the current C2 address. Operators rotate C2 by submitting a small blockchain transaction rather than registering new domains, which gives takedown resilience and makes traffic resemble legitimate wallet or API activity.

TONResolver communicates over a WebSocket channel using ECDH (secp256k1) key exchange, HKDF-SHA256 key derivation and AES-256-CBC, with a 20-second ping/pong keepalive. Message types 0-8 cover keepalives, key exchange, endpoint information (username, hostname, OS, CPU, memory, MAC address), arbitrary JavaScript execution, result return, file retrieval/execution and PowerShell execution. Trend Micro observed second-stage malware dropped in the user Temp folder that accessed Chrome and Edge data directories, interacted with lsass.exe and read browser SQLite databases (passwords, cookies, history, autofill), indicating credential theft. The TON contract C2 domain history is: amanohuguta.cfd (2026-02-07), hsaertyuoang34.sbs (2026-02-09), zloapobikahy23.bond (2026-02-20), tonajukbhuakpo2.shop (2026-06-02).

Attribution: no named actor. Cofense assesses with moderate confidence that this continues earlier Booking.com-themed phishing that delivered PureRAT or NetSupport Manager via ClickFix pages, while noting that shared tooling used by separate groups could also explain the similarities. Severity is the analyst's judgment, not a source-stated rating. Note: an unrelated EtherRAT campaign reported by Sysdig (React2Shell exploitation, Linux persistence, linked to DPRK Contagious Interview overlap) uses a different Ethereum contract and is not evidenced as linked to this hotel campaign.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1059.007 JavaScript
- T1547.001 Registry Run Keys / Startup Folder
- T1036.008 Masquerade File Type
- T1027 Obfuscated Files or Information
- T1555.003 Credentials from Web Browsers
- T1003.001 LSASS Memory
- T1082 System Information Discovery
- T1102.001 Dead Drop Resolver
- T1568 Dynamic Resolution
- T1573.001 Symmetric Cryptography
- T1204.001 User Execution
- T1140 Deobfuscate/Decode Files or Information
- T1105 Ingress Tool Transfer
- T1071.001 Application Layer Protocol
- T1583.001 Domains
- T1562.001 Impair Defenses
- T1005 Data from Local System
- T1571 Non-Standard Port
- T1041 Exfiltration Over C2 Channel

## Sources

- [Hackers Use Negative Hotel Reviews to Spread Malware That Hides C2 on Blockchain](https://cybersecuritynews.com/negative-hotel-reviews/)
- [From Guest Complaints to Malware: Blockchain Abuse Targets Hotels (Cofense)](https://cofense.com/blog/from-guest-complaints-to-malware-blockchain-abuse-targets-hotels)
- [Phishing Campaign Targets Japan's Hotels Using TONResolver RAT (Trend Micro)](https://www.trendmicro.com/en_us/research/26/f/tonresolver.html)
- [EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks (Sysdig, related but separate EtherRAT campaign)](https://www.sysdig.com/blog/etherrat-dprk-uses-novel-ethereum-implant-in-react2shell-attacks)
- [EtherRAT Techniques Bypass Security Via Ethereum Smart Contracts (Infosecurity Magazine)](https://infosecurity-magazine.com/news/etherrat-bypass-security-ethereum)
- [TONResolver RAT abuses TON blockchain to target Japan's hotels (ThreatCluster)](https://threatcluster.io/cluster/tonresolver-rat-abuses-ton-blockchain-to-target-japans-hotel-ed768283)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3093
