Executive Summary
Since April 2026, a sophisticated phishing campaign has targeted front-desk and reservation systems in the hospitality sector across Europe and Asia. The campaign, which Microsoft has not yet attributed to a specific actor, leverages "authentication laundering" by routing malicious links through legitimate services like Calendly and Google to bypass email security protocols (SPF/DKIM/DMARC). The lures are often themed around guest complaints or room inquiries in Japanese, Danish, and Dutch.
The technical execution involves a multi-stage chain where victims download a ZIP archive containing a malicious LNK file. This shortcut triggers PowerShell to download a portable Node.js runtime and a JavaScript implant known as TonRAT. TonRAT is notable for using the TON blockchain API to resolve its Command and Control (C2) domains, complicating static blocklisting efforts. The campaign represents a significant risk to the hospitality sector due to its durable persistence mechanisms and the use of legitimate infrastructure to establish a foothold.
