Phishing campaign targeting hotels: ‘photo’ ZIP installs Node.js implant (TonRAT) — Microsoft alert

Colleagues, note a cybersecurity campaign: since April attackers impersonate guest complaints and drop ZIPs with “photos”.
- Microsoft: mails route via Calendly and Google redirects — SPF/DKIM/DMARC checks pass.
- Inside the ZIP: an LNK launching PowerShell; the script installs Node.js in user space and deploys a JavaScript implant (TonRAT).
- The implant resolves C2 via the TON blockchain API and uses nonstandard ports; signs of browser automation and remote shutdown observed.
Why this matters: primary vector is reception and booking systems; simple cleanup leaves artifacts.
What immediate measures do you recommend?
#cybersecurity #phishing #NodeJS #incident

