Hackers establish persistence in hospitality and hotels by impersonating guests with poisoned ZIP archives, but no one knows what their plan is


  • Microsoft Threat Intelligence Warns of Phishing Campaign Targeting Hotel Staff in Europe and Asia Using Guest Complaint-Themed Emails
  • Attackers abuse services like Calendly and Google redirects to bypass authentication checks and deliver photo-themed ZIP files that install a persistent Node.js implant
  • Malware disables Defender, runs C2 beaconing, collects system information and forces shutdowns; signs include unusual PowerShell activity, Node.js execution, and suspicious registry entries

Hackers are establishing a foothold in hotels and hospitality organizations across Europe and Asia, but no one really knows for what, at least not yet.

This is according to Microsoft Threat Intelligence, which recently published a new report saying that since April it has tracked an active phishing campaign. In this campaign, the unnamed attackers target front desk, front desk, and reservation staff with emails about guest complaints, room conditions, bed bug infestations, booking inquiries, and the like.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top