Microsoft reported an active phishing campaign targeting hotel and hospitality organizations across Europe and Asia, using booking-, complaint-, and photo-themed emails to pressure recipients into opening malicious ZIP archives. The messages were routed through trusted services including Calendly and Google redirects, and in later activity used Cloudflare-fronted .cfd domains to evade detection. The ZIP files contained fake PNG shortcut (.LNK) files that launched obfuscated PowerShell, then installed a Node.js-based implant Microsoft tracks as TonRAT; Microsoft said the campaign has been active since April and evolved across multiple waves while keeping the same core infrastructure and tradecraft.
On compromised systems, the attackers established persistence through HKCU\Run and HKCU\RunOnce, added Microsoft Defender process exclusions, and staged payloads in Temp and ProgramData, with some later samples dynamically compiling .NET DLLs via csc.exe and cvtres.exe. TonRAT communicated over encrypted WebSockets and used the TON blockchain API for command-and-control domain resolution, while Microsoft also observed beaconing on non-standard ports such as 56001 and 56002, browser automation, geolocation lookups through ip-api.com, and forced shutdown commands. Microsoft has not attributed the activity to a known threat actor or confirmed follow-on ransomware or data theft, but said the operator is investing in obfuscation, persistence, and delivery evasion to maintain access for later actions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On June 29, 2026, Trend Micro published analysis of a phishing campaign targeting Japanese accommodation facilities that are Booking.com partners in May and June 2026. The report described the TONResolver RAT, including its use of the TON blockchain via TonAPI to resolve rotating C2 infrastructure and its likely follow-on credential theft activity.
On June 25, 2026, Microsoft Threat Intelligence published technical details on the Photo ZIP campaign, including its delivery chain, persistence mechanisms, and post-compromise behavior. Microsoft said it had not attributed the activity to a known threat actor.
Microsoft observed the intrusion set evolve from Wave 1 to Wave 2 while retaining core infrastructure and behaviors. Changes included PHOTO-prefixed LNK filenames, dynamic .NET DLL compilation via csc.exe and cvtres.exe, and phishing domains fronted by Cloudflare using .cfd domains.
Microsoft said an active multi-stage intrusion campaign has targeted hotel and hospitality organizations in Europe and Asia since April 2026. The campaign used phishing emails routed through Calendly and Google redirects to deliver photo-themed ZIP archives containing malicious LNK files that launched PowerShell and installed the Node.js-based TonRAT implant.
TrendAI Research said the phishing campaign against Booking.com partner accommodations primarily targeted Japan but also hit hospitality organizations in Austria, Australia, France, Germany, Indonesia, Italy, the Netherlands, Russia, South Korea, Turkey, the UK, and the US. This expanded the known victim scope of the TONResolver campaign beyond Japanese hotels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcecybersecuritynews.com
Open sourceinfosecurity-magazine.com
Open sourcecommunity.gurucul.com
Open sourcethehackernews.com
Open sourcemicrosoft.com
Open sourcesocprime.com
Open sourceblog.itochuci.co.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.