Skip to content
Andorra Cybersecurity Agency Warns Hotels of Spear-Phishing Malware Attack

Andorra Cybersecurity Agency Warns Hotels of Spear-Phishing Malware Attack

Alto.Ad • August 29, 2026

Andorra's National Cybersecurity Agency (ANC-AD) has issued an urgent alert an active spear-phishing campaign targeting hotel reception staff, confirming at least one device infection and urging immediate checks of reservation and inboxes.

The attacks involve emails in English sent from free messaging accounts. They impersonate angry guests alleging physical assaults by hotel employees and demanding a response within 48 hours to avoid legal action. Each message contains a link that passes through legitimate Google infrastructure before redirecting to attacker-controlled domains. Clicking leads to a compressed archive download with malware disguised as a photo.

The agency highlighted the campaign's sophistication. The malware is polymorphic, producing unique variants on every download to bypass signature-based detection tools. The malicious server also delivers files selectively to specific browsers and operating systems, dodging routine analysis and organizational protections.

This approach enables attackers to access confidential data, posing a high risk to Andorra's tourism sector. ANC-AD stressed simple preventive steps: hotels must notify reception teams right away, avoid opening compressed attachments without IT checks, enable file extension visibility on reception computers, and verify security protocols with technology providers.

The warning, released on 28 August 2026, calls for swift incident reporting to limit the threat's spread.

Other articles from Catalan-language sources the same story:

L'Agència de Ciberseguretat alerta els hotels d'atacs informàtics de suplantació d'identitat

Alerta per una campanya de ciberatacs dirigida als hotels d’Andorra

Extracted Entities

Attack Types (2)

Companies (1)

Countries (1)