Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Hikvision Camera Vulnerability CVE-2021-36260 Targeted by Attackers
October 8, 2026
Fake Firefox Wallet Extensions Steal Crypto Recovery Phrases
October 8, 2026
Critical Tensorlake npm Package Flaw Spreads Shai-Hulud Worm, Steals Dev Secrets
October 8, 2026
Home/CyberSecurity News/Hackers Hide C2 on Blockchain via Negative Hotel Review Malware
CyberSecurity News

Hackers Hide C2 on Blockchain via Negative Hotel Review Malware

Key Takeaways Cybercriminals are targeting hotels with sophisticated phishing emails disguised as negative guest reviews. The campaign deploys EtherRAT or TONResolver malware, which leverage public...

Emy Elsamnoudy
Emy Elsamnoudy
October 8, 2026 5 Min Read
3 0

Key Takeaways

  • Cybercriminals are targeting hotels with sophisticated phishing emails disguised as negative guest reviews.
  • The campaign deploys EtherRAT or TONResolver malware, which leverage public blockchains (Ethereum and TON) to dynamically retrieve their command and control (C2) server addresses.
  • This blockchain-based C2 infrastructure makes traditional takedown efforts less effective as removing a server does not erase the blockchain record pointing to its replacement.
  • The attacks bypass static signature checks by utilizing LNK files disguised as images and varying dummy file sizes.
  • Hotel staff, particularly those in front desk, reservations, and guest relations, are the primary targets, pressured by concerns over reputation.

Sophisticated Phishing Campaign Targets Hotels with Blockchain-Enabled Malware

A new, highly targeted cyberattack campaign is preying on the reputation concerns of hotels by delivering malware through fake negative guest reviews. These deceptive emails lead hotel staff to download malicious files, which are presented as photographic evidence of fabricated complaints.

Table Of Content

  • Key Takeaways
  • Sophisticated Phishing Campaign Targets Hotels with Blockchain-Enabled Malware
  • Evolution of Attack Vectors and Malware Delivery
  • How EtherRAT and TONResolver Utilize Blockchains for C2
  • What You Should Do

The campaign’s payload consists of either EtherRAT or TONResolver, two advanced malware families. A defining characteristic of these threats is their innovative use of public blockchains to locate their command and control (C2) servers, a significant departure from traditional methods that embed fixed addresses within the malware itself. This technique, known as blockchain dead drop resolving, enhances the resilience of the C2 infrastructure against conventional takedown attempts.

The malicious emails are meticulously crafted to appear as legitimate customer feedback, often landing in the inboxes of front desk, reservations, and guest relations teams. These departments are particularly vulnerable due to their daily responsibilities involving customer inquiries and complaints. The messages frequently describe severe issues such as unsanitary conditions, disputes with employees, or even threats of legal action, creating a sense of urgency and pressure on staff to investigate.

Links embedded within these emails purport to offer photographic evidence, videos, or crucial documents related to the complaint. This tactic exploits the hotel’s imperative to protect its brand image, compelling employees to open potentially dangerous files under the guise of resolving a customer issue.

Researchers from Cofense identified both EtherRAT and TONResolver in these ongoing campaigns. Intelligence analyst Kahng An detailed these findings in an October 7 report. Cofense assesses with moderate confidence that these activities represent a continuation of earlier phishing campaigns that targeted Booking.com users. However, the use of shared malware tools across different threat groups could also account for the observed similarities, making definitive attribution challenging.

Evolution of Attack Vectors and Malware Delivery

Previous iterations of these attacks involved fake booking messages and “ClickFix” pages that instructed staff to execute commands directly within the Windows Run window. These earlier campaigns predominantly deployed PureRAT or NetSupport Manager. While previous reporting on compromised hotel booking accounts has illustrated how such infections can facilitate broader fraud schemes, Cofense has not yet confirmed similar outcomes in the current campaign.

The current wave of emails directs recipients to an archive file containing a malicious Windows shortcut (.LNK file). This LNK file is cleverly disguised as a JPG image. Instead of displaying a photograph, opening this file executes malicious code. The archive also includes a dummy MP4 file, whose size is deliberately varied with each download. This variation likely aims to generate different hashes, thereby weakening the effectiveness of static file signature-based detection methods.

Upon execution, the shortcut downloads Node.js, a legitimate JavaScript runtime environment, and subsequently installs either the EtherRAT or TONResolver malware family. Both malware strains leverage Node.js for their operations. Cofense notes that this shared approach suggests a possible common loader being utilized, though it does not definitively prove a single threat actor is behind all operations. Furthermore, researchers assess with moderate confidence that the attackers are employing generative AI to diversify the wording of their phishing emails, making them more difficult to detect through simple keyword matching.

How EtherRAT and TONResolver Utilize Blockchains for C2

EtherRAT operates by querying an Ethereum smart contract via a public JSON-RPC service, typically using a request like eth_call. It then decodes the hexadecimal data returned and applies a light masking removal process to extract the current C2 domain or IP address. Earlier analyses of EtherRAT’s blockchain hiding techniques have documented this design in other attack contexts, though these do not establish a direct link to the operators of this specific hotel campaign.

TONResolver employs a similar methodology but leverages a public TON blockchain API. It retrieves C2 information from data associated with a specific wallet or smart contract on the TON network. Previous reporting on TONResolver’s abuse of smart contracts has also described hotel phishing campaigns utilizing comparable delivery mechanisms. The primary distinction between the two malware families in this context is simply which blockchain network is used to supply the C2 address, rather than a fundamental difference in their reliance on external command servers.

This “blockchain dead drop resolving” technique ensures that the blockchain itself does not function as the command server. Instead, it acts as a dynamic directory, storing instructions that point to the actual C2 infrastructure. This allows operators to publish new C2 destinations through a blockchain transaction, enabling already infected devices to locate replacement servers without requiring a new malware file to be distributed. This resilience significantly complicates takedown efforts that typically focus on compromising or shutting down domains or hosting accounts. The removal of a C2 server does not eliminate the blockchain record that directs infected devices to its successor.

Furthermore, public blockchain API requests can easily blend in with legitimate wallet or network traffic, making them harder to distinguish and block. Cofense highlights that blocking access to Ethereum alone would still leave TON access available if the campaign were to utilize the other malware family, underscoring the need for comprehensive security measures.

What You Should Do

  • Educate Staff: Provide comprehensive training to all employees, especially those in customer-facing roles, on how to identify and report suspicious emails. Emphasize that even urgent complaint links or threats should be treated with caution.
  • Verify Unexpected Links: Instruct staff to verify the legitimacy of any unexpected links, especially those promising photos or documents, before clicking. This can involve hovering over links to check URLs or contacting the supposed sender through an established, official channel.
  • Implement Email Security: Deploy advanced email security solutions with robust anti-phishing, anti-malware, and sandboxing capabilities to detect and block malicious emails before they reach end-users.
  • Monitor for Unusual Activity: Security teams should actively monitor hotel workstations for unusual Node.js activity or unexpected network connections. Investigate any instances where legitimate runtimes or blockchain services appear to be facilitating suspicious downloads or communications.
  • Strengthen Endpoint Security: Ensure endpoint detection and response (EDR) solutions are deployed and properly configured to detect and prevent the execution of malicious LNK files and subsequent malware installations.
  • Review Public Inboxes: Extend vigilance to publicly listed customer support, sales, and business development email addresses, as these are often targeted by similar phishing attempts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants

Next Post

Microsoft Teams Fights Deepfakes With AI-Powered Audio and Video Detection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Hide C2 on Blockchain via Negative Hotel Review Malware
October 8, 2026
Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants
October 8, 2026
Critical LMCache Flaw (CVE-2024-XXXX) Gets PoC, Enables RCE
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us