Hackers Hide C2 on Blockchain via Negative Hotel Review Malware
Key Takeaways Cybercriminals are targeting hotels with sophisticated phishing emails disguised as negative guest reviews. The campaign deploys EtherRAT or TONResolver malware, which leverage public...
Key Takeaways
- Cybercriminals are targeting hotels with sophisticated phishing emails disguised as negative guest reviews.
- The campaign deploys EtherRAT or TONResolver malware, which leverage public blockchains (Ethereum and TON) to dynamically retrieve their command and control (C2) server addresses.
- This blockchain-based C2 infrastructure makes traditional takedown efforts less effective as removing a server does not erase the blockchain record pointing to its replacement.
- The attacks bypass static signature checks by utilizing LNK files disguised as images and varying dummy file sizes.
- Hotel staff, particularly those in front desk, reservations, and guest relations, are the primary targets, pressured by concerns over reputation.
Sophisticated Phishing Campaign Targets Hotels with Blockchain-Enabled Malware
A new, highly targeted cyberattack campaign is preying on the reputation concerns of hotels by delivering malware through fake negative guest reviews. These deceptive emails lead hotel staff to download malicious files, which are presented as photographic evidence of fabricated complaints.
Table Of Content
The campaign’s payload consists of either EtherRAT or TONResolver, two advanced malware families. A defining characteristic of these threats is their innovative use of public blockchains to locate their command and control (C2) servers, a significant departure from traditional methods that embed fixed addresses within the malware itself. This technique, known as blockchain dead drop resolving, enhances the resilience of the C2 infrastructure against conventional takedown attempts.
The malicious emails are meticulously crafted to appear as legitimate customer feedback, often landing in the inboxes of front desk, reservations, and guest relations teams. These departments are particularly vulnerable due to their daily responsibilities involving customer inquiries and complaints. The messages frequently describe severe issues such as unsanitary conditions, disputes with employees, or even threats of legal action, creating a sense of urgency and pressure on staff to investigate.
Links embedded within these emails purport to offer photographic evidence, videos, or crucial documents related to the complaint. This tactic exploits the hotel’s imperative to protect its brand image, compelling employees to open potentially dangerous files under the guise of resolving a customer issue.
Researchers from Cofense identified both EtherRAT and TONResolver in these ongoing campaigns. Intelligence analyst Kahng An detailed these findings in an October 7 report. Cofense assesses with moderate confidence that these activities represent a continuation of earlier phishing campaigns that targeted Booking.com users. However, the use of shared malware tools across different threat groups could also account for the observed similarities, making definitive attribution challenging.
Evolution of Attack Vectors and Malware Delivery
Previous iterations of these attacks involved fake booking messages and “ClickFix” pages that instructed staff to execute commands directly within the Windows Run window. These earlier campaigns predominantly deployed PureRAT or NetSupport Manager. While previous reporting on compromised hotel booking accounts has illustrated how such infections can facilitate broader fraud schemes, Cofense has not yet confirmed similar outcomes in the current campaign.
The current wave of emails directs recipients to an archive file containing a malicious Windows shortcut (.LNK file). This LNK file is cleverly disguised as a JPG image. Instead of displaying a photograph, opening this file executes malicious code. The archive also includes a dummy MP4 file, whose size is deliberately varied with each download. This variation likely aims to generate different hashes, thereby weakening the effectiveness of static file signature-based detection methods.
Upon execution, the shortcut downloads Node.js, a legitimate JavaScript runtime environment, and subsequently installs either the EtherRAT or TONResolver malware family. Both malware strains leverage Node.js for their operations. Cofense notes that this shared approach suggests a possible common loader being utilized, though it does not definitively prove a single threat actor is behind all operations. Furthermore, researchers assess with moderate confidence that the attackers are employing generative AI to diversify the wording of their phishing emails, making them more difficult to detect through simple keyword matching.
How EtherRAT and TONResolver Utilize Blockchains for C2
EtherRAT operates by querying an Ethereum smart contract via a public JSON-RPC service, typically using a request like eth_call. It then decodes the hexadecimal data returned and applies a light masking removal process to extract the current C2 domain or IP address. Earlier analyses of EtherRAT’s blockchain hiding techniques have documented this design in other attack contexts, though these do not establish a direct link to the operators of this specific hotel campaign.
TONResolver employs a similar methodology but leverages a public TON blockchain API. It retrieves C2 information from data associated with a specific wallet or smart contract on the TON network. Previous reporting on TONResolver’s abuse of smart contracts has also described hotel phishing campaigns utilizing comparable delivery mechanisms. The primary distinction between the two malware families in this context is simply which blockchain network is used to supply the C2 address, rather than a fundamental difference in their reliance on external command servers.
This “blockchain dead drop resolving” technique ensures that the blockchain itself does not function as the command server. Instead, it acts as a dynamic directory, storing instructions that point to the actual C2 infrastructure. This allows operators to publish new C2 destinations through a blockchain transaction, enabling already infected devices to locate replacement servers without requiring a new malware file to be distributed. This resilience significantly complicates takedown efforts that typically focus on compromising or shutting down domains or hosting accounts. The removal of a C2 server does not eliminate the blockchain record that directs infected devices to its successor.
Furthermore, public blockchain API requests can easily blend in with legitimate wallet or network traffic, making them harder to distinguish and block. Cofense highlights that blocking access to Ethereum alone would still leave TON access available if the campaign were to utilize the other malware family, underscoring the need for comprehensive security measures.
What You Should Do
- Educate Staff: Provide comprehensive training to all employees, especially those in customer-facing roles, on how to identify and report suspicious emails. Emphasize that even urgent complaint links or threats should be treated with caution.
- Verify Unexpected Links: Instruct staff to verify the legitimacy of any unexpected links, especially those promising photos or documents, before clicking. This can involve hovering over links to check URLs or contacting the supposed sender through an established, official channel.
- Implement Email Security: Deploy advanced email security solutions with robust anti-phishing, anti-malware, and sandboxing capabilities to detect and block malicious emails before they reach end-users.
- Monitor for Unusual Activity: Security teams should actively monitor hotel workstations for unusual Node.js activity or unexpected network connections. Investigate any instances where legitimate runtimes or blockchain services appear to be facilitating suspicious downloads or communications.
- Strengthen Endpoint Security: Ensure endpoint detection and response (EDR) solutions are deployed and properly configured to detect and prevent the execution of malicious LNK files and subsequent malware installations.
- Review Public Inboxes: Extend vigilance to publicly listed customer support, sales, and business development email addresses, as these are often targeted by similar phishing attempts.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.