Cyber Security News

Hackers Target Hotels With Fake Guest Complaints to Deploy Blockchain-Based RAT Malware

Hackers are targeting hotels with fabricated guest complaints and negative reviews to distribute EtherRAT and TONResolver, two malware families that abuse public blockchains to locate their command-and-control infrastructure.

The activity appears to extend earlier Booking. com-themed phishing operations, although Cofense assesses that connection with moderate confidence.

Similar email templates and accommodation-sector targeting link the campaigns.

However, the newer attacks replace fake CAPTCHA instructions with downloadable files designed to exploit hotel employees’ obligation to investigate guest concerns.

Messages reach front-desk, reservations, and guest-relations personnel, presenting everything from dirty-room complaints to allegations of staff harassment and legal threats.

Some arrive as replies after an apparently legitimate conversation, adding credibility and pressure to review purported evidence.

Embedded links download an archive containing a malicious LNK shortcut masquerading as a JPG image and a dummy MP4 file.

Windows shortcuts normally point to files or applications, but these weaponized shortcuts execute instructions rather than display the promised photograph.

The dummy video changes size between downloads. Cofense believes this variation likely produces different archive hashes, weakening detection that depends exclusively on previously identified file fingerprints.

Executing the shortcut downloads a legitimate Node.js runtime, which subsequently runs either EtherRAT or TONResolver.

Cofense also assesses with moderate confidence that attackers use generative AI to produce varied messages.

That remains an analytical judgment rather than confirmed attribution, but the diversity of complaint narratives complicates detection based on repeated wording.

Both payloads use blockchain data as a directory for their current C2 destination, rather than relying on a fixed domain embedded in the malware.

Cofense Intelligence’s analysis describes campaigns, that turn routine customer correspondence into an infection pathway, using malicious Windows shortcuts disguised as photographic evidence.

Fake Guest Complaint Phishing

The blockchain supplies the address; the attacker-controlled server remains the operational communication endpoint.

EtherRAT queries an Ethereum smart contract through a public JSON-RPC endpoint.

A recent email that delivers EtherRAT via a link purporting to have evidence of an unclean room (Source : Cofense).

A read request retrieves encoded data, which the malware decodes and deobfuscates into a domain or IP address. Operators can update the stored destination through transactions without redistributing the payload.

TONResolver follows the same principle using public TON APIs to retrieve data associated with a wallet or smart contract.

Cofense observed multiple destinations associated with each family, illustrating how operators rotate infrastructure while retaining the same on-chain reference.

Their shared Node.js execution model suggests possible common loader infrastructure, not definitive proof of a single operator.

Using different blockchains also diversifies resolution services: restricting Ethereum access alone would not address a payload consulting TON.

The approach aligns with MITRE ATT&CK’s Dead Drop Resolver technique, T1102.001, which describes legitimate services hosting pointers to secondary C2 infrastructure.

MITRE notes that such indirection improves operational resilience and can obscure backend infrastructure during malware analysis.

Blockchain records resist conventional removal requests, but the external C2 servers remain disruptable.

Domain blocking alone may therefore interrupt communication without eliminating an infection’s ability to discover replacement infrastructure.

The campaign also connects to Cofense’s earlier Booking.com-spoofing ClickFix analysis, where fake verification pages persuaded users to run clipboard-delivered commands.

Defenders should correlate suspicious shortcut execution, unexpected runtime deployment, and subsequent resolver traffic, rather than treating blockchain API requests as inherently malicious.

MITRE recommends enforcing external-service policies and detecting processes that retrieve obfuscated pointers to secondary servers.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago