Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Highlights Hotel Phishing Threat with Node.js

Microsoft Highlights Hotel Phishing Threat with Node.js

Posted on June 26, 2026 By CWS

An ongoing phishing operation has been targeting the hotel industry across Europe and Asia since April 2026. According to Microsoft, attackers are using ZIP files with photo themes to deploy a Node.js implant, compromising machines at the front desk of hospitality establishments.

Tactics and Techniques

The campaign has not been linked to any known threat actors, and the ultimate motive remains uncertain. The phishing emails mimic hotel operations with a display name of “Booking Manager (via Calendly)” and mention issues like guest complaints and health inspections. The emails, primarily in Japanese, Danish, and Dutch, lack specific recipient names, indicating a broad, list-driven tactic rather than targeted spear phishing.

The attackers employ a sophisticated delivery method, routing emails through Calendly’s notification system and Google’s URL redirect service, a method Microsoft describes as authentication laundering. These emails pass crucial verification checks, appearing legitimate as they are sent through authorized channels.

Technical Details

The attack chain involves a multi-hop link from a Calendly email through Google redirects to a newly registered domain protected by Cloudflare. The final payload is a ZIP file, seemingly containing images, but in reality, a shortcut that activates a PowerShell script. This script decodes a concealed download URL, fetching a Node.js runtime and executing a JavaScript implant.

The malware, identified as TonRAT, communicates with its control servers via the TON blockchain API and uses encrypted WebSockets, complicating static blocklist defenses. The implant sends signals to specific IP addresses over uncommon ports, and some systems show signs of headless browser automation and forced shutdown commands.

Impact and Mitigation

While no data theft or ransomware incidents have been confirmed by Microsoft, the persistent access provided by the implant is concerning. Remediation requires addressing both the RunOnce entry in ProgramData and the Node.js Run key, as well as removing runtime files under AppDataLocalNodejs to ensure complete removal.

Previous reports from SOC Prime and ITOCHU have documented similar phishing tactics within the hotel industry. This campaign follows a pattern of booking-themed phishing attempts targeting hotel personnel, a tactic seen in past ClickFix campaigns aimed at stealing Booking.com credentials.

The unresolved question is the attackers’ ultimate goal. With durable access and a challenging cleanup process, the situation demands serious attention from affected organizations.

The Hacker News Tags:Asia, Calendly, Cloudflare, Cybersecurity, Europe, hotel security, Malware, Microsoft, Node.js, Phishing, SOC Prime

Post navigation

Previous Post: KuinaExtractor Malware Evades Detection with New Tactics
Next Post: Polymarket Hack Exposes $3 Million Security Breach

Related Posts

Securing Data in the AI Era Securing Data in the AI Era The Hacker News
Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition The Hacker News
GreatXML Exploit Circumvents Windows BitLocker Security GreatXML Exploit Circumvents Windows BitLocker Security The Hacker News
ShinyHunters Exploit Oracle Zero-Day to Target Universities ShinyHunters Exploit Oracle Zero-Day to Target Universities The Hacker News
China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks The Hacker News
RaccoonO365 Phishing Network Dismantled as Microsoft, Cloudflare Take Down 338 Domains RaccoonO365 Phishing Network Dismantled as Microsoft, Cloudflare Take Down 338 Domains The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Linux Foundation Launches Akrites for Open Source Security
  • Miasma Malware Targets npm and GitHub in New Attack
  • Python.org Flaw Exposed Admin API Access Risks
  • Polymarket Hack Exposes $3 Million Security Breach
  • Microsoft Highlights Hotel Phishing Threat with Node.js

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Linux Foundation Launches Akrites for Open Source Security
  • Miasma Malware Targets npm and GitHub in New Attack
  • Python.org Flaw Exposed Admin API Access Risks
  • Polymarket Hack Exposes $3 Million Security Breach
  • Microsoft Highlights Hotel Phishing Threat with Node.js

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark