Executive Summary
Since April 2026, a sophisticated phishing campaign has been targeting hotel and hospitality organizations across Europe and Asia. Attackers send emails impersonating 'Booking Manager (via Calendly)' with subjects referencing guest complaints or health inspections. These emails contain links leading to ZIP files named 'photo-<numbers>.zip,' which, when opened, execute a Node.js-based remote access trojan (RAT) called TonRAT. The malware establishes command-and-control channels through the TON blockchain API, complicating detection and mitigation efforts. This incident underscores the evolving tactics of cybercriminals who exploit trusted platforms like Calendly and Google’s URL redirect services to bypass traditional email security measures. The use of Node.js implants and blockchain-based command-and-control mechanisms highlights the need for organizations to enhance their cybersecurity defenses against increasingly sophisticated phishing campaigns.
Why This Matters Now
The campaign's exploitation of trusted services and advanced malware delivery methods signifies a shift in phishing tactics, making traditional security measures less effective. Organizations must adapt to these evolving threats to protect sensitive data and maintain operational integrity.
Attack Path Analysis
Attackers initiated the campaign by sending phishing emails to hotel staff, leading to the download of a malicious ZIP file containing a shortcut that executed a PowerShell script. This script installed a Node.js runtime and executed a JavaScript implant, TonRAT, which established an encrypted WebSocket connection to the attacker's command-and-control server. The malware allowed attackers to execute commands remotely, potentially leading to data exfiltration and further malicious activities.
Kill Chain Progression
Initial Compromise
Description
Attackers sent phishing emails to hotel staff, leading to the download of a malicious ZIP file containing a shortcut that executed a PowerShell script.
MITRE ATT&CK® Techniques
Spearphishing Attachment
JavaScript
Malicious File
Process Injection
Web Protocols
File and Directory Discovery
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Hospitality
Hotel front-desk systems directly targeted by Node.js phishing campaign, compromising guest data, payment processing, and operational security across European and Asian properties.
Leisure/Travel
Travel organizations face lateral movement risks from compromised hospitality partners, threatening booking systems, customer data, and integrated reservation platforms through east-west traffic.
Financial Services
Payment processing vulnerabilities exposed through hospitality sector breaches, requiring enhanced egress security and encrypted traffic controls to prevent data exfiltration from hotel transactions.
Information Technology/IT
IT service providers managing hospitality infrastructure must implement zero trust segmentation and multicloud visibility to detect Node.js implants and prevent privilege escalation attacks.
Sources
- Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implanthttps://thehackernews.com/2026/06/microsoft-warns-of-photo-zip-phishing.htmlVerified
- Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaignhttps://www.microsoft.com/en-us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/Verified
- Phishing campaign impersonates Booking.com, delivers a suite of credential-stealing malwarehttps://www.microsoft.com/en-us/security/blog/2025/03/13/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to execute unauthorized scripts would likely be constrained, reducing the risk of initial malware deployment.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, limiting their access to sensitive resources.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the risk of widespread compromise.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command-and-control channels would likely be constrained, limiting their control over compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data would likely be constrained, reducing the risk of data loss.
The overall impact of the attack would likely be constrained, reducing the potential for significant data loss or operational disruption.
Impact at a Glance
Affected Business Functions
- Front Desk Operations
- Reservation Management
- Guest Services
- Billing and Payment Processing
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of guest personal information, including names, contact details, and payment information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement advanced email filtering to detect and block phishing attempts.
- • Restrict execution of PowerShell scripts to prevent unauthorized code execution.
- • Monitor for unauthorized installations of Node.js runtime and execution of JavaScript implants.
- • Enhance network monitoring to detect and block unauthorized WebSocket connections.
- • Educate staff on recognizing and reporting phishing emails to reduce the risk of initial compromise.



