Hackers Target Hotel Staff Across Europe and Asia with Phishing Campaign
Executive Briefing
- Targets front desk and reservations staff with guest complaint emails in multiple languages since April 2025.
- Abuses Calendly and Google redirects to bypass SPF, DKIM, and DMARC email authentication checks.
- Delivers poisoned ZIP archives containing fake image shortcuts that install a persistent Node.js implant.
- Malware disables Microsoft Defender, runs C2 beaconing, collects system data, and forces shutdowns.
- Microsoft believes activity signals reconnaissance, likely preceding a ransomware or destructive attack.
Sponsored