Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Photo-themed phishing campaign targets European and Asian hotels with Node.js implant

A sophisticated phishing campaign is targeting hotels in Europe and Asia using photo-themed ZIP files delivered via emails that bypass security via Calendly and Google URL redirects. The attack chain downloads a PowerShell script that installs a Node.js runtime to deploy the TonRAT implant, which communicates via the TON blockchain API and establishes persistence through RunOnce entries. The article does not specify a software vulnerability, CVSS score, affected versions, or a patch; remediation requires thorough cleaning of infected front-desk systems.
Read Full Article →

Phishing Photo-themed phishing campaign targets European and Asian hotels with Node.js implant June 29, 2026 Share By SC Staff (Adobe Stock) A sophisticated phishing campaign has been actively targeting hotel and hospitality organizations across Europe and Asia since April 2026, according to Microsoft. The attackers are using photo-themed ZIP files to deliver a Node.js implant, aiming to compromise front-desk machines. This campaign has been observed using techniques to bypass email security measures, The Hacker News reports. The campaign, which Microsoft has not attributed to a known threat actor, uses lures referencing common hotel operational issues like guest complaints, bedbug infestations, and health inspections. Emails are sent via Calendly and Google's URL redirect service, a method termed "authentication laundering" by Microsoft, to bypass SPF, DKIM, and DMARC checks. Victims are directed through multiple redirects to a malicious .cfd domain. Upon clicking, they download a ZIP file containing a shortcut disguised as an image. Executing this shortcut triggers a PowerShell script that decodes a hidden URL, downloads a .ps1 file, and installs a legitimate Node.js runtime to execute the TonRAT implant. This implant communicates with its command and control servers using the TON blockchain API and opens an encrypted WebSocket channel. While the attackers' ultimate goal remains unclear, the persistence mechanisms involve RunOnce entries and Node.js Run keys, requiring thorough remediation on reception, reservation, and front office systems. Source: The Hacker News SC Staff Related Phishing Scammers abuse Shopify’s Shop app with fake receipts SC Staff June 26, 2026 Scammers are impersonating well-known brands like Norton, McAfee, Apple, and PayPal by adding fake orders to the Shop app, which is popular in North America with over 50 million downloads on Google Play. Phishing New ‘Blacksite’ phishing kit bundles AiTM with scanner evasion Laura French June 25, 2026 The kit includes Cloaked.gg, which displays benign sites to detected scanners and sandboxes. Phishing EvilTokens phishing service scales attacks 1,380% with AI integration SC Staff June 24, 2026 The Huntress report highlights how EvilTokens operates like a modern tech startup, offering sophisticated phishing capabilities through subscription tiers ranging from $600 to $1,500. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article