Phishing Campaign Targets Japanese Hotels with Multi-Stage Malware

Phishing Campaign Targets Japanese Hotels with Multi-Stage Malware

9h ago Socprime 87% similarity 72.5
Share:

Article Content

Browse articles
ThreatCluster

A phishing campaign impersonating Booking.com has targeted hotel operators in Japan, utilizing emails with malicious attachments. The attack employs a multi-stage malware process involving a ZIP archive containing a malicious LNK file that executes PowerShell scripts. This leads to the deployment of TonRAT, a Node.js-based remote access trojan. The malware establishes command-and-control communications via a WebSocket endpoint, dynamically obtained through the TON API, complicating traditional defense measures. Security recommendations include blocking suspicious links, monitoring PowerShell activity, and isolating affected endpoints. The investigation provides file hashes and command-and-control domains for further analysis. Organizations are advised to enhance email filtering and restrict execution of untrusted scripts.

Key Points: • Phishing emails disguised as Booking.com notifications target Japanese hotels. • The attack utilizes a multi-stage process involving PowerShell and TonRAT malware. • Defenders should monitor for unusual PowerShell activity and restrict execution of LNK files.

ThreatCluster AI

Timeline

2026-06-12
Phishing campaign identified
A phishing campaign targeting hotel operators in Japan was reported, utilizing malicious emails with attachments.
Socprime
2026-06-12
Malware execution chain detailed
The attack was found to involve a ZIP archive with a malicious LNK file that executes PowerShell scripts to deploy TonRAT.
Socprime
2026-06-12
Command-and-control method revealed
The malware uses the TON API to dynamically obtain command-and-control domains, complicating defenses.
Socprime

Community

Browse all →