HomeSecurityMicrosoft warns of phishing campaign targeting hotels

Microsoft warns of phishing campaign targeting hotels

According to Microsoft, an campaign phishing is targeting hotels and other hospitality companies across Europe and Asia, using photo-themed ZIP files to install a Node.js implant and infiltrate front-desk machines.

Microsoft warns of phishing campaign targeting hotels

The company has not attributed the activity to a known threat actor, and the ultimate goal of the operators remains unclear.

How does the phishing attack target hotels?

The trap exploits the way hotels operate. The phishing emails are named “Booking Manager (via Calendly)” and refer to customer complaints, bed bug infestations, room inquiries, health inspections, and accommodation reviews.

See also: Microsoft: Clipper malware campaign targets Windows

The phishing scams appeared in Japanese, Danish and Dutch, with Japanese being the most common. The subject line does not mention a recipient or ownership, suggesting a mass mailing, based on a list, rather than targeted spear phishing. The attackers pressure victims because they have issues related to the hotel's reputation: complaints, final warnings, inspections.

The interesting part is delivery. Operators route messages through Calendly and Google’s URL redirection service, a trick that Microsoft calls “authentication laundering.” Emails sent through Calendly’s direct route pass SPF, DKIM, and DMARC because they’re actually being sent from an authorized infrastructure.

Article Image: Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

The checks confirm that the sender is authorized to send. They say nothing about the purpose of the message. A multi-step chain leads the victim from a Calendly link via share.google and a Google redirect to a newly registered, Cloudflare-protected .cfd domain. This domain is behind a Turnstile challenge that also acts as an anti-analysis.

When the target clicks, it downloads a file named photo-Inside there is a shortcut pretending to be an image: IMG- in the first wave, PHOTO- in the second.

Opening it launches PowerShell. The script uses BigInt arithmetic to decode a hidden download URL, pulls a .ps1 into %TEMP% , and installs a legitimate Node.js runtime v24.13.0 from nodejs.org into user space, which then executes the JavaScript implant. No system-level installation of Node is required.

See also: GHOST STADIUM: Phishing campaign targets FIFA World Cup 2026 fans

TonRAT implant

The implant is tracked as TonRAT. It resolves C2 domains via the TON blockchain API and then opens an encrypted WebSocket channel, according to SOC Prime. Dynamic domain retrieval makes static block lists less useful.

After compromise, the implant broadcasts to fixed IPs via non-standard ports: 8443, 8445, 8453, 5555, and 56001 to 56003. Some hosts also showed headless browser automation (–headless –no-sandbox), ip-api.com geolocation check , and forced shutdown via cmd /c shutdown -s -t 0.

Microsoft has not reported any confirmed data theft, ransomware, or specific victims.

Microsoft warns of phishing campaign targeting hotels

Protection

A complete remediation involves getting rid of both persistence paths: the RunOnce entry pointing to ProgramData and the Node.js Run key, as well as the runtime and .js files under AppData\Local\Nodejs. Removing one leaves the other “alive.” The front desk, reservations, and office systems are the first places to check.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: FBI: Kali365 phishing service targets Microsoft 365 accounts

This campaign is yet another reminder that the hospitality industry remains one of the most attractive targets for cybercriminals. Hotels manage large volumes of personal data, payment information and reservation systems that must remain constantly available, which increases the pressure on staff and creates ideal conditions for social engineering attacks. Attackers exploit this need for immediate response to complaints and reputation issues, turning normal business processes into entry points into corporate networks.

While there have been no reported data breaches or ransomware attacks linked to the campaign, the technical sophistication of the attack suggests that threats are evolving faster than traditional defenses. The use of trusted services such as Calendly and Google redirects, combined with the use of Node.js and blockchain to communicate with control servers, demonstrates that modern phishing is no longer limited to suspicious emails and random links. For tourism businesses, continuous staff training and the adoption of advanced detection mechanisms are now a prerequisite and not just an additional security measure.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS