VMTech
Discuss a project

Phishing campaign targeting hotels: ‘photo’ ZIP installs Node.js implant (TonRAT) — Microsoft alert

Phishing campaign targeting hotels: ‘photo’ ZIP installs Node.js implant (TonRAT) — Microsoft alert

Colleagues, note a cybersecurity campaign: since April attackers impersonate guest complaints and drop ZIPs with “photos”.

- Microsoft: mails route via Calendly and Google redirects — SPF/DKIM/DMARC checks pass.
- Inside the ZIP: an LNK launching PowerShell; the script installs Node.js in user space and deploys a JavaScript implant (TonRAT).
- The implant resolves C2 via the TON blockchain API and uses nonstandard ports; signs of browser automation and remote shutdown observed.

Why this matters: primary vector is reception and booking systems; simple cleanup leaves artifacts.

What immediate measures do you recommend?

#cybersecurity #phishing #NodeJS #incident

Open analytics
On the site 2 views
min read 1 28.06.2026
On Instagram 4 views
On Instagram 1 reach
Instagram

Phishing campaign targeting hotels: ‘photo’ ZIP installs Node.js implant (TonRAT) — Microsoft alert

Open the post on Instagram ↗