Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Highlights Hotel Phishing Threat with Node.js

Microsoft Highlights Hotel Phishing Threat with Node.js

Posted on June 26, 2026 By CWS

An ongoing phishing operation has been targeting the hotel industry across Europe and Asia since April 2026. According to Microsoft, attackers are using ZIP files with photo themes to deploy a Node.js implant, compromising machines at the front desk of hospitality establishments.

Tactics and Techniques

The campaign has not been linked to any known threat actors, and the ultimate motive remains uncertain. The phishing emails mimic hotel operations with a display name of “Booking Manager (via Calendly)” and mention issues like guest complaints and health inspections. The emails, primarily in Japanese, Danish, and Dutch, lack specific recipient names, indicating a broad, list-driven tactic rather than targeted spear phishing.

The attackers employ a sophisticated delivery method, routing emails through Calendly’s notification system and Google’s URL redirect service, a method Microsoft describes as authentication laundering. These emails pass crucial verification checks, appearing legitimate as they are sent through authorized channels.

Technical Details

The attack chain involves a multi-hop link from a Calendly email through Google redirects to a newly registered domain protected by Cloudflare. The final payload is a ZIP file, seemingly containing images, but in reality, a shortcut that activates a PowerShell script. This script decodes a concealed download URL, fetching a Node.js runtime and executing a JavaScript implant.

The malware, identified as TonRAT, communicates with its control servers via the TON blockchain API and uses encrypted WebSockets, complicating static blocklist defenses. The implant sends signals to specific IP addresses over uncommon ports, and some systems show signs of headless browser automation and forced shutdown commands.

Impact and Mitigation

While no data theft or ransomware incidents have been confirmed by Microsoft, the persistent access provided by the implant is concerning. Remediation requires addressing both the RunOnce entry in ProgramData and the Node.js Run key, as well as removing runtime files under AppDataLocalNodejs to ensure complete removal.

Previous reports from SOC Prime and ITOCHU have documented similar phishing tactics within the hotel industry. This campaign follows a pattern of booking-themed phishing attempts targeting hotel personnel, a tactic seen in past ClickFix campaigns aimed at stealing Booking.com credentials.

The unresolved question is the attackers’ ultimate goal. With durable access and a challenging cleanup process, the situation demands serious attention from affected organizations.

The Hacker News Tags:Asia, Calendly, Cloudflare, Cybersecurity, Europe, hotel security, Malware, Microsoft, Node.js, Phishing, SOC Prime

Post navigation

Previous Post: KuinaExtractor Malware Evades Detection with New Tactics
Next Post: Polymarket Hack Exposes $3 Million Security Breach

Related Posts

Secret Blizzard Deploys Malware in ISP-Level AitM Attacks on Moscow Embassies Secret Blizzard Deploys Malware in ISP-Level AitM Attacks on Moscow Embassies The Hacker News
Critical Flaw in MCP Protocol Poses Major AI Supply Chain Risk Critical Flaw in MCP Protocol Poses Major AI Supply Chain Risk The Hacker News
Enhancing Incident Response: Key Operational Essentials Enhancing Incident Response: Key Operational Essentials The Hacker News
MuddyWater Intensifies Cyber Attacks in MENA with New Malware MuddyWater Intensifies Cyber Attacks in MENA with New Malware The Hacker News
New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands The Hacker News
Identity Security Has an Automation Problem—And It’s Bigger Than You Think Identity Security Has an Automation Problem—And It’s Bigger Than You Think The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Nebulock Secures $25M for Advanced AI Security
  • New Linux Kernel Flaw DirtyClone Allows Root Access
  • Hackers Exploit Shopify’s Shop App with Phony Invoices
  • Linux Foundation Launches Akrites for Open Source Security
  • Miasma Malware Targets npm and GitHub in New Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Nebulock Secures $25M for Advanced AI Security
  • New Linux Kernel Flaw DirtyClone Allows Root Access
  • Hackers Exploit Shopify’s Shop App with Phony Invoices
  • Linux Foundation Launches Akrites for Open Source Security
  • Miasma Malware Targets npm and GitHub in New Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark