malware
Published 2026-10-07
Verified 2026-10-09

Cofense: fake guest complaints and bad-review emails lure hotel front-desk staff into running EtherRAT or TONResolver, malware that looks up its command server on the Ethereum or TON blockchain

Cofense Intelligence reported on 7 October 2026 on email campaigns against the accommodation industry that pose as guest complaints or negative reviews, describing dirty rooms, disputes with staff or threatened legal action, and link to supposed photo, video or document evidence. The link gives an archive holding a Windows shortcut (LNK) disguised as a JPG, plus a dummy MP4 whose size changes on each download so file hashes keep changing. Opening the shortcut downloads Node.js and installs EtherRAT or TONResolver. EtherRAT reads an Ethereum smart contract through a public JSON-RPC service to recover its current command server; TONResolver does the same through a public TON blockchain API. Because the server address lives on a public blockchain, the operator can move servers with one transaction and existing infections follow, which blunts domain or hosting takedowns, and the lookups resemble normal wallet traffic. Cofense assesses with moderate confidence that this continues earlier Booking.com-themed phishing that used ClickFix pages to deliver PureRAT or NetSupport Manager, and that generative AI is used to vary the email wording. Primary: Cofense Intelligence; wire: Cyber Security News.

Product
Windows PCs at hotels and accommodation providers
Versions
n/a — phishing campaign
Exploited in Australia?
unknown
Patch to
Warn front-desk and reservations teams about complaint emails with download links. Block LNK files inside archives at the mail gateway, alert on Node.js being downloaded and run from user folders, and watch for endpoints calling public Ethereum or TON API services when they have no business reason to.

Primary: Cofense — From guest complaints to malware: blockchain abuse targets hotels (7 Oct 2026) · Cyber Security News — Hackers use negative hotel reviews to spread malware that hides C2 on blockchain (8 Oct 2026)

tech identity network