Photo ZIP Campaign Delivers TonRAT to Hospitality
Score: 8/10

Photo ZIP Campaign Delivers TonRAT to Hospitality

An active phishing campaign targets hospitality organizations in Europe and Asia using photo-themed ZIP files to deliver a Node.js-based implant called TonRAT.

Executive Summary

Since April 2026, a sophisticated phishing campaign has targeted front-desk and reservation systems in the hospitality sector across Europe and Asia. The campaign, which Microsoft has not yet attributed to a specific actor, leverages "authentication laundering" by routing malicious links through legitimate services like Calendly and Google to bypass email security protocols (SPF/DKIM/DMARC). The lures are often themed around guest complaints or room inquiries in Japanese, Danish, and Dutch.

The technical execution involves a multi-stage chain where victims download a ZIP archive containing a malicious LNK file. This shortcut triggers PowerShell to download a portable Node.js runtime and a JavaScript implant known as TonRAT. TonRAT is notable for using the TON blockchain API to resolve its Command and Control (C2) domains, complicating static blocklisting efforts. The campaign represents a significant risk to the hospitality sector due to its durable persistence mechanisms and the use of legitimate infrastructure to establish a foothold.

Key Details

Threat Name

TonRAT

Affects

—

Adversary

—

Malware/Tools

TonRAT, PureRAT, Wacatac

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources