Hackers Target Hotel Staff Across Europe and Asia with Phishing Campaign
Executive Briefing
- Targets front desk and reservations staff with guest complaint emails in multiple languages since April 2025.
- Abuses Calendly and Google redirects to bypass SPF, DKIM, and DMARC email authentication checks.
- Delivers poisoned ZIP archives containing fake image shortcuts that install a persistent Node.js implant.
- Malware disables Microsoft Defender, runs C2 beaconing, collects system data, and forces shutdowns.
- Microsoft believes activity signals reconnaissance, likely preceding a ransomware or destructive attack.
Sponsored
Automatic Mouthwash Dispenser
$34.99
EMEET 1080P Webcam with Microphone, C960 Web Camera, 2 Mics Streaming Webcam, 90°FOV Computer Camera, Plug and Play USB Web Cam for Online Calling/Conferencing
$37.99
Traeger Grills Pro 34 Electric Wood Pellet Grill & Smoker
$499.00
Toy CyberTruck w/Trailer & ATV
$19.99