Hackers are exploiting the hospitality sector by sending fake complaints and negative reviews to hotels, which result in staff inadvertently downloading malware. These malicious campaigns utilize either EtherRAT or TONResolver malware, which cleverly use public blockchains to find their command and control (C2) servers, bypassing traditional fixed-address methods.
How Hackers Target Hotels
Emails containing false complaints are sent to hotel front desks, reservations, and guest relations teams. These messages describe various issues like unclean rooms or disputes, pressuring staff into downloading supposed evidence like photos or videos. This tactic exploits the staff’s duty to maintain the hotel’s reputation, prompting them to open malicious files.
Research by Cofense, detailed in an October 7 report, highlights these campaigns. They suggest a connection to earlier phishing attempts targeting Booking.com, although shared malware tools could indicate multiple groups’ involvement.
Techniques Behind the Malware
Previous attacks used fake booking confirmations and ClickFix pages, tricking staff into executing commands in the Windows Run window. These methods often deployed PureRAT or NetSupport Manager malware. The new wave of emails links to an archive containing a malicious LNK file disguised as a JPG image, which runs executable code instead of displaying a photo.
This LNK file also downloads Node.js, a legitimate JavaScript runtime, to install either malware. The shared use of Node.js suggests a common loader for both malware types. Additionally, researchers believe attackers may use AI to vary email wording, making detection harder.
Blockchain Techniques in Malware Operations
Both EtherRAT and TONResolver employ blockchain technology to locate C2 servers. EtherRAT reads Ethereum smart contracts via a public JSON-RPC service, while TONResolver uses a TON blockchain API. This technique, known as blockchain dead drop resolving, provides a resilient way to manage C2 server locations without direct server involvement.
Such methods complicate efforts to dismantle networks by targeting specific domains or servers, as the blockchain records remain intact. Cofense advises that simply blocking Ethereum access may not suffice, as TON access could still be exploited.
What Hotels Can Do
Hotel staff are urged to treat unexpected complaint emails with suspicion, regardless of their urgent tone. Training to identify malicious emails is crucial, beyond relying on fixed wording or hash checks. Security teams should monitor unusual Node.js activity and correlate it with email records to enhance threat detection.
In conclusion, the use of blockchain technology in malware campaigns presents a formidable challenge. Hotels must remain vigilant, employing comprehensive security measures to protect against these evolving cyber threats.
