TonRAT is a Node.js-based remote access trojan used in phishing campaigns targeting hospitality organizations, particularly hotel operators and front-desk environments in Europe and Asia. It has been delivered through booking-themed social engineering lures, including fake guest complaints and bedbug-related messages, with victims redirected to archives containing malicious Windows shortcut files. Execution typically begins with a PowerShell-based loader chain that decrypts an obfuscated JavaScript payload, installs or reuses a legitimate Node.js runtime, and launches the implant in user space.
The malware combines remote access and downloader functionality. It performs host reconnaissance by collecting system and user information, establishes persistence through Windows autorun mechanisms, and communicates with operators over encrypted WebSocket channels. TonRAT supports arbitrary command execution and can download and run additional payloads, enabling broader post-compromise activity. Observed tradecraft also includes defense evasion measures such as heavy JavaScript obfuscation, hidden PowerShell execution, mutex use, and the addition of Microsoft Defender exclusions in some intrusion chains.
A distinctive feature of TonRAT is its use of The Open Network (TON) ecosystem for command-and-control discovery. Rather than relying on a fixed embedded domain, the implant queries a public TON API to retrieve current C2 domain information associated with attacker-controlled blockchain data, allowing operators to rotate infrastructure without rebuilding the malware. After resolving the active endpoint, TonRAT establishes an encrypted session using a key-exchange mechanism and then protects subsequent traffic with symmetric encryption over WebSocket.
TonRAT has been associated with Booking.com-themed phishing operations and broader hospitality-focused intrusion activity observed in 2026. Public reporting has not conclusively attributed the campaign to a named threat actor. The malware’s delivery chain, resilient persistence, dynamic C2 resolution, and support for follow-on payload execution indicate its role as a flexible access platform for sustained compromise of Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
今回、当社が観測した攻撃には以下の特徴があります。… 難読化された PowerShell ローダー、JavaScript ファイル
PowerShell コマンドがファイル内の暗号化された JavaScript ファイル(TonRAT)を復号し、ファイルとして書き出す
Victims are directed through multiple redirects to a malicious .cfd domain.
Invoke-WebRequest を使用してハードコードされている通信先から別の PowerShell ファイルを取得し、実行します。
The implant supports remote code execution. It can download and run Windows programs, plus PowerShell and JavaScript.
129 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Node.js-based backdoor delivered via booking-themed phishing emails targeting hotel staff. It uses a malicious LNK and PowerShell to install or leverage Node.js, decrypt and run an obfuscated JavaScript payload, establish persistence, fetch C2 information from the TON blockchain via the EtherHiding technique, open an encrypted WebSocket channel, execute remote commands, download and run additional payloads, and add a Microsoft Defender exclusion for its dropped file.
Named by the content as a malware/tool associated with the described Node.js implant campaign delivering persistent access.
A Node.js-based remote access implant delivered via phishing ZIP files targeting hotel and hospitality organizations. It is executed through a PowerShell-based infection chain, uses the TON blockchain API for command-and-control communications, opens an encrypted WebSocket channel, and establishes persistence via RunOnce entries and Node.js Run keys.
A JavaScript-based implant executed via a user-space Node.js runtime, used in a phishing campaign against hospitality organizations. It establishes persistence through HKCU\Run and a self-refreshing HKCU\RunOnce mechanism, reconnects to C2 infrastructure, and can resume delivering additional payloads after partial remediation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.