Skip to content
Phishing Campaign Targets Japanese Hotels with Multi-Stage Malware

Phishing Campaign Targets Japanese Hotels with Multi-Stage Malware

First seen 12 Jun 2026, 13:38 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 13, 2026 at 13:23 UTC
  • Phishing emails disguised as Booking.com notifications target Japanese hotels.
  • The attack utilizes a multi-stage process involving PowerShell and TonRAT malware.
  • Defenders should monitor for unusual PowerShell activity and restrict execution of LNK files.

A phishing campaign impersonating Booking.com has targeted hotel operators in Japan, utilizing emails with malicious attachments. The attack employs a multi-stage malware process involving a ZIP archive containing a malicious LNK file that executes PowerShell scripts. This leads to the deployment of TonRAT, a Node.js-based remote access trojan. The malware establishes command-and-control communications via a WebSocket endpoint, dynamically obtained through the TON API, complicating traditional defense measures. Security recommendations include blocking suspicious links, monitoring PowerShell activity, and isolating affected endpoints. The investigation provides file hashes and command-and-control domains for further analysis. Organizations are advised to enhance email filtering and restrict execution of untrusted scripts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-06-12
Phishing campaign identified
A phishing campaign targeting hotel operators in Japan was reported, utilizing malicious emails with attachments.
Socprime
2026-06-12
Malware execution chain detailed
The attack was found to involve a ZIP archive with a malicious LNK file that executes PowerShell scripts to deploy TonRAT.
Socprime
2026-06-12
Command-and-control method revealed
The malware uses the TON API to dynamically obtain command-and-control domains, complicating defenses.
Socprime

More articles in this cluster (2)

Following this threat?

Track TonRAT and Booking.com in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed