Hackers Use Negative Hotel Reviews to Spread Malware That Hides C2 on Blockchain
Cofense says hotel staff are phished with fake complaints that deliver EtherRAT and TONResolver using blockchain C2.
Cofense reported that attackers email hotel front-desk and guest-relations staff with fake negative reviews and complaint links that lead to malware. Archives contain a Windows LNK shortcut disguised as a photo; opening it downloads Node.js and installs EtherRAT or TONResolver. EtherRAT reads an Ethereum smart contract over a public JSON-RPC service to recover its command-and-control address, while TONResolver uses a TON blockchain API, a method known as dead-drop resolving. Cofense assesses with moderate confidence that the activity continues earlier Booking.com phishing that delivered PureRAT or NetSupport Manager, and that generative AI may vary the email wording.