Hospitality organizations in Europe and Asia are being targeted with booking- and complaint-themed phishing emails carrying ZIP archives that contain malicious Windows shortcut (.LNK) files disguised as images or reservation documents. Researchers said the lures have referenced customer complaints, bed bug incidents, health alerts, and booking inquiries, and in some cases abused Calendly infrastructure and Google redirects to bypass email authentication controls. When opened, the shortcut launches hidden PowerShell to reconstruct or fetch the next-stage payload, install a legitimate Node.js runtime if needed, and execute an obfuscated JavaScript backdoor; some observed variants also dynamically compiled a .NET DLL via csc.exe and cvtres.exe before starting the implant.
The malware establishes persistence through Windows Registry Run keys, with Microsoft also observing dual persistence via HKCU\Run and HKCU\RunOnce, and attempts to weaken defenses by adding Microsoft Defender exclusions. Investigators reported command-and-control infrastructure hidden behind Cloudflare, use of rotating .cfd domains, and in newer samples an EtherHiding-style technique that queries the TON blockchain through TONAPI to obtain current C2 addresses before communicating over encrypted WebSocket channels using ECDH/HKDF/AES. Post-compromise behavior included beaconing, headless browser automation, geolocation lookups, payload download and execution, and forced system shutdowns; LevelBlue linked more than 400 related LNK samples through a shared MachineID, indicating an active and operationally mature campaign.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that the earliest observed samples associated with the hospitality phishing campaign date back to March 2026. This pushes the known activity window earlier than previously documented public observations.
LevelBlue reported observing daily new samples and more than 400 related LNK files sharing a common MachineID, indicating the operation is ongoing and mature. Reporting also noted infrastructure protected behind Cloudflare and encrypted WebSocket communications for the backdoor.
LevelBlue described an active multi-stage campaign targeting the hospitality sector with booking-themed ZIP archives containing malicious LNK files that ultimately run a Node.js backdoor. The researchers said the malware used EtherHiding by querying the TON blockchain through TONAPI to retrieve its current C2 address instead of hardcoding it.
Microsoft reported a second wave in which PowerShell dynamically compiled a .NET DLL via csc.exe and cvtres.exe before launching a Node.js-based implant. The malware also used dual persistence through HKCU\Run and HKCU\RunOnce and added Microsoft Defender process exclusions.
In the campaign's first wave, malicious LNK files launched obfuscated PowerShell to download a script and deploy Node.js. The malware then established persistence and began post-compromise activity including C2 beaconing and other host actions.
Microsoft documented an active intrusion campaign observed since April 2026 targeting hospitality organizations in Europe and Asia with photo-themed ZIP archives containing malicious LNK files disguised as PNG images. The lures used themes such as customer complaints, bed bug infestations, and health alerts in Japanese, Danish, and Dutch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcelevelblue.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.