Skip to content
Hotels Targeted by Phishing Campaigns Using Fake Guest Complaints

Hotels Targeted by Phishing Campaigns Using Fake Guest Complaints

First seen 8 Oct 2026, 12:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 13:30 UTC

Hackers are targeting the hotel industry with phishing emails containing fabricated guest complaints to deliver EtherRAT and TONResolver malware. These emails, which appear to be a continuation of previous Booking.com-themed attacks, exploit hotel employees' responsibilities to investigate guest issues. The emails include malicious LNK shortcut files disguised as images, which execute commands to download the malware. Cofense Intelligence assesses this campaign with moderate confidence, noting the use of generative AI to create varied complaint narratives. The malware utilizes public blockchain data for command-and-control infrastructure, complicating detection efforts. The attacks leverage the accommodation sector's customer service dynamics, posing a significant risk to hotel operations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-08
Cofense reports on hotel phishing campaigns
Cofense Intelligence details ongoing phishing campaigns targeting hotels with fake guest complaints delivering malware.
Cofense
2026-10-08
Gbhackers report on phishing tactics
Gbhackers outlines how hackers use fake complaints to deploy malware in hotels, linking it to previous Booking.com phishing efforts.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track EtherRAT and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What types of malware are being used?
The phishing campaign delivers EtherRAT and TONResolver, which are both remote access trojans.
Who is primarily affected by this attack?
The hotel industry, specifically front-desk and guest-relations personnel, are the main targets of these phishing emails.
How can hotels protect themselves?
Hotels should educate staff about phishing tactics and implement email filtering solutions to detect malicious attachments.