Andorra Cybersecurity Agency Warns Hotels of Spear-Phishing Malware Attack
Andorra's National Cybersecurity Agency (ANC-AD) has issued an urgent alert an active spear-phishing campaign targeting hotel reception staff, confirming at least one device infection and urging immediate checks of reservation and inboxes.
The attacks involve emails in English sent from free messaging accounts. They impersonate angry guests alleging physical assaults by hotel employees and demanding a response within 48 hours to avoid legal action. Each message contains a link that passes through legitimate Google infrastructure before redirecting to attacker-controlled domains. Clicking leads to a compressed archive download with malware disguised as a photo.
The agency highlighted the campaign's sophistication. The malware is polymorphic, producing unique variants on every download to bypass signature-based detection tools. The malicious server also delivers files selectively to specific browsers and operating systems, dodging routine analysis and organizational protections.
This approach enables attackers to access confidential data, posing a high risk to Andorra's tourism sector. ANC-AD stressed simple preventive steps: hotels must notify reception teams right away, avoid opening compressed attachments without IT checks, enable file extension visibility on reception computers, and verify security protocols with technology providers.
The warning, released on 28 August 2026, calls for swift incident reporting to limit the threat's spread.
Other articles from Catalan-language sources the same story:
L'Agència de Ciberseguretat alerta els hotels d'atacs informàtics de suplantació d'identitat
Alerta per una campanya de ciberatacs dirigida als hotels d’Andorra
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
