Darkreading Phishing Campaign Targets Hospitality Sector in Europe and Asia
Article Content
- •Phishing emails target hotel staff with malicious zip files disguised as photos.
- •Attackers gain persistent access to systems by executing malware via Windows shortcuts.
- •Microsoft and Trend Micro have reported similar phishing campaigns in Europe and Asia.
A phishing campaign has been launched against hotels in Europe and Asia, utilizing malicious zip files disguised as guest photos to install malware. Attackers impersonate guests with complaints, tricking hotel employees into opening these files. The zip files contain Windows shortcuts masquerading as images, which execute commands to download malware when opened. Microsoft and Trend Micro have both reported on the activity, which began in April and May 2026. The malware allows attackers to gain persistent access to systems, steal sensitive information, and potentially install additional malware. The campaign has affected multiple hotels across Belgium, Ireland, the Netherlands, and Japan, with investigations underway into the breaches. The attackers exploit trusted services to bypass email authentication checks, making the phishing attempts more convincing.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track TONResolver and Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…