Node.js Malware Campaign Targets Hospitality Industry with Photo Phishing

Node.js Malware Campaign Targets Hospitality Industry with Photo Phishing

First seen 26 Jun 2026, 09:08 UTC Blogs.MicrosoftFeeds.4SysopsThehackernews 77% similarity 67.5
Share:

Article Content

Browse articles
ThreatCluster

A multi-stage cyberattack campaign has been identified, targeting the hospitality sector in Europe and Asia since April 2026. The attackers utilize 'authentication laundering' techniques, exploiting legitimate services like Calendly and Google redirects to bypass email security measures. Phishing attempts often involve fake guest complaints or room inquiries, tricking staff into downloading malicious ZIP files that contain deceptive image shortcuts. These files deliver a persistent Node.js implant, allowing attackers to maintain access to compromised systems. The campaign highlights the evolving tactics of cybercriminals and their focus on specific industries. Microsoft Threat Intelligence has confirmed the ongoing nature of this threat, emphasizing the need for heightened security awareness in the hospitality sector.

Key Points: • The hospitality industry in Europe and Asia is under attack from a Node.js malware campaign. • Attackers use photo-themed phishing lures and authentication laundering to evade detection. • Malicious ZIP files containing fake image shortcuts deliver a persistent Node.js implant.

ThreatCluster AI

Timeline

2026-04-01
Cyberattack campaign began
A multi-stage cyberattack targeting the hospitality industry started, leveraging phishing tactics.
Feeds.4Sysops
2026-06-25
Microsoft identifies ongoing campaign
Microsoft Threat Intelligence confirmed the active Node.js implant campaign affecting hospitality organizations.
Blogs.Microsoft
2026-06-26
Public disclosure of threat
Microsoft published findings on the Node.js malware campaign, urging affected organizations to enhance their security measures.
Feeds.4Sysops

Community

Browse all →