Phishing Campaign Targets Japan's Hotels Using TONResolver RAT

Phishing Campaign Targets Japan's Hotels Using TONResolver RAT

First seen 29 Jun 2026, 22:43 UTC Feeds.TrendmicroTrendmicroGbhackersInfosecurity-MagazineCybersecuritynews 91% similarity 66.5
Share:

Article Content

Browse articles
ThreatCluster

In late May 2026, a phishing campaign targeting Japan's hotel industry was identified, utilizing emails that impersonated guest complaints to deliver the TONResolver RAT. The emails, sent to Booking.com partner accommodations, contained malicious links leading to a ZIP file with a disguised shortcut file (LNK) that installed the TrojanSpy.JS.TONRESOLVER.A malware. This malware exploits the TON blockchain as a dead drop resolver, complicating detection and takedown efforts. Japanese hotels were primarily targeted, although other countries were also affected. The attack method bypassed traditional email security measures like SPF, DKIM, and DMARC. The persistent nature of the malware poses ongoing risks for credential theft and further compromises. Trend Micro's TrendAI Research confirmed the attack's details and scope, emphasizing the sophistication of the phishing tactics employed.

Key Points: • Phishing emails targeted Booking.com partners in Japan with guest complaint lures. • The TONResolver RAT uses the TON blockchain for command-and-control evasion. • Traditional email security measures failed to prevent these sophisticated attacks.

ThreatCluster AI

Timeline

2026-05-29
Phishing emails identified targeting hotels
TrendAI Research detected phishing emails sent to Japanese Booking.com partners, impersonating guest complaints.
Trendmicro
2026-06-29
Trend Micro publishes findings on TONResolver RAT
Trend Micro reported on the TONResolver RAT's use of the TON blockchain and its impact on Japan's hotel industry.
Trendmicro
2026-06-30
Infosecurity Magazine reports on the attack's scope
Infosecurity Magazine highlighted that the phishing campaign also targeted hotels in various countries beyond Japan.
Infosecurity-Magazine

Community

Browse all →