Phishing Campaign Targets Japanese Hotels via Booking.com, Delivers Blockchain-Hosted Malware (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Phishing emails sent via scheduling tool to bypass SPF/DKIM/DMARC.
- TONResolver malware uses TON blockchain for C2 resolution.
- Follow-on attacks target Japanese hospitality organizations primarily.
"A wave of phishing emails sent to Booking.com partner accommodations in Japan in May 2026 led to the deployment of TONResolver malware, hosted on the TON blockchain. The emails, posing as guest review requests, tricked hotel staff into executing malicious LNK files. The malware functions as a remote access trojan, enabling credential theft and further compromise. The campaign was detected by TrendAI Research."
no comments yet.