Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Highlights Hotel Phishing Threat with Node.js

Microsoft Highlights Hotel Phishing Threat with Node.js

Posted on June 26, 2026 By CWS

An ongoing phishing operation has been targeting the hotel industry across Europe and Asia since April 2026. According to Microsoft, attackers are using ZIP files with photo themes to deploy a Node.js implant, compromising machines at the front desk of hospitality establishments.

Tactics and Techniques

The campaign has not been linked to any known threat actors, and the ultimate motive remains uncertain. The phishing emails mimic hotel operations with a display name of “Booking Manager (via Calendly)” and mention issues like guest complaints and health inspections. The emails, primarily in Japanese, Danish, and Dutch, lack specific recipient names, indicating a broad, list-driven tactic rather than targeted spear phishing.

The attackers employ a sophisticated delivery method, routing emails through Calendly’s notification system and Google’s URL redirect service, a method Microsoft describes as authentication laundering. These emails pass crucial verification checks, appearing legitimate as they are sent through authorized channels.

Technical Details

The attack chain involves a multi-hop link from a Calendly email through Google redirects to a newly registered domain protected by Cloudflare. The final payload is a ZIP file, seemingly containing images, but in reality, a shortcut that activates a PowerShell script. This script decodes a concealed download URL, fetching a Node.js runtime and executing a JavaScript implant.

The malware, identified as TonRAT, communicates with its control servers via the TON blockchain API and uses encrypted WebSockets, complicating static blocklist defenses. The implant sends signals to specific IP addresses over uncommon ports, and some systems show signs of headless browser automation and forced shutdown commands.

Impact and Mitigation

While no data theft or ransomware incidents have been confirmed by Microsoft, the persistent access provided by the implant is concerning. Remediation requires addressing both the RunOnce entry in ProgramData and the Node.js Run key, as well as removing runtime files under AppDataLocalNodejs to ensure complete removal.

Previous reports from SOC Prime and ITOCHU have documented similar phishing tactics within the hotel industry. This campaign follows a pattern of booking-themed phishing attempts targeting hotel personnel, a tactic seen in past ClickFix campaigns aimed at stealing Booking.com credentials.

The unresolved question is the attackers’ ultimate goal. With durable access and a challenging cleanup process, the situation demands serious attention from affected organizations.

The Hacker News Tags:Asia, Calendly, Cloudflare, Cybersecurity, Europe, hotel security, Malware, Microsoft, Node.js, Phishing, SOC Prime

Post navigation

Previous Post: KuinaExtractor Malware Evades Detection with New Tactics
Next Post: Polymarket Hack Exposes $3 Million Security Breach

Related Posts

Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year The Hacker News
The ROI Problem in Attack Surface Management The ROI Problem in Attack Surface Management The Hacker News
AI-Driven Worm Revolutionizes Cybersecurity Threats AI-Driven Worm Revolutionizes Cybersecurity Threats The Hacker News
Critical Weaver E-cology Flaw Exploited via Debug API Critical Weaver E-cology Flaw Exploited via Debug API The Hacker News
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide The Hacker News
CTEM’s Core: Prioritization and Validation CTEM’s Core: Prioritization and Validation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns
  • Critical Progress LoadMaster Vulnerability Alert: Exploitation Detected
  • Cisco Discloses Critical ClamAV Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows WalletService Flaw Could Lead to Privilege Escalation
  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns
  • Critical Progress LoadMaster Vulnerability Alert: Exploitation Detected
  • Cisco Discloses Critical ClamAV Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark