The Containment Era is here. →Explore

Executive Summary

Since April 2026, a sophisticated phishing campaign has been targeting hotel and hospitality organizations across Europe and Asia. Attackers send emails impersonating 'Booking Manager (via Calendly)' with subjects referencing guest complaints or health inspections. These emails contain links leading to ZIP files named 'photo-<numbers>.zip,' which, when opened, execute a Node.js-based remote access trojan (RAT) called TonRAT. The malware establishes command-and-control channels through the TON blockchain API, complicating detection and mitigation efforts. This incident underscores the evolving tactics of cybercriminals who exploit trusted platforms like Calendly and Google’s URL redirect services to bypass traditional email security measures. The use of Node.js implants and blockchain-based command-and-control mechanisms highlights the need for organizations to enhance their cybersecurity defenses against increasingly sophisticated phishing campaigns.

Why This Matters Now

The campaign's exploitation of trusted services and advanced malware delivery methods signifies a shift in phishing tactics, making traditional security measures less effective. Organizations must adapt to these evolving threats to protect sensitive data and maintain operational integrity.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attackers send emails impersonating 'Booking Manager (via Calendly)' containing links to ZIP files that deploy a Node.js-based remote access trojan called TonRAT.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to execute unauthorized scripts would likely be constrained, reducing the risk of initial malware deployment.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges would likely be constrained, limiting their access to sensitive resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the risk of widespread compromise.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command-and-control channels would likely be constrained, limiting their control over compromised systems.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate data would likely be constrained, reducing the risk of data loss.

Impact (Mitigations)

The overall impact of the attack would likely be constrained, reducing the potential for significant data loss or operational disruption.

Impact at a Glance

Affected Business Functions

  • Front Desk Operations
  • Reservation Management
  • Guest Services
  • Billing and Payment Processing
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of guest personal information, including names, contact details, and payment information.

Recommended Actions

  • Implement advanced email filtering to detect and block phishing attempts.
  • Restrict execution of PowerShell scripts to prevent unauthorized code execution.
  • Monitor for unauthorized installations of Node.js runtime and execution of JavaScript implants.
  • Enhance network monitoring to detect and block unauthorized WebSocket connections.
  • Educate staff on recognizing and reporting phishing emails to reduce the risk of initial compromise.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image