Hotels Targeted by Phishing Campaigns Using Fake Guest Complaints
Article Content
- •Phishing emails target hotel staff with fake complaints to deliver malware.
- •Malware families EtherRAT and TONResolver exploit public blockchain data.
- •Attackers use generative AI to create varied phishing messages.
Hackers are targeting the hotel industry with phishing emails containing fabricated guest complaints to deliver EtherRAT and TONResolver malware. These emails, which appear to be a continuation of previous Booking.com-themed attacks, exploit hotel employees' responsibilities to investigate guest issues. The emails include malicious LNK shortcut files disguised as images, which execute commands to download the malware. Cofense Intelligence assesses this campaign with moderate confidence, noting the use of generative AI to create varied complaint narratives. The malware utilizes public blockchain data for command-and-control infrastructure, complicating detection efforts. The attacks leverage the accommodation sector's customer service dynamics, posing a significant risk to hotel operations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track EtherRAT and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What types of malware are being used?
Who is primarily affected by this attack?
How can hotels protect themselves?
Continue Reading
New ChainScript RAT Exploits ClickFix Lures with Blockchain C2 A newly discovered Node.js remote access trojan (RAT) named ChainScript is being deployed through ClickFix social engineering tactics, targeting Windows systems. The malware utilizes a unique command-and-control (C2) discovery method by querying a Polygon blockchain smart contract to dynamically rotate its server…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…