Hackers Target Hotels With Fake Guest Complaints to Deploy Blockchain-Based RAT Malware
Hotel staff are phished with fake guest complaints that deliver EtherRAT and TONResolver using blockchain C2 lookups.
Cofense says attackers are emailing hotel front-desk, reservations, and guest-relations staff with fabricated guest complaints, harassment claims, and legal threats. Links download an archive holding a malicious LNK shortcut disguised as a JPG plus a dummy MP4 whose size changes to evade hash-based detection. The shortcut fetches a legitimate Node.js runtime that launches EtherRAT or TONResolver. Those payloads read Ethereum smart-contract data or TON wallet data to obtain rotatable command-and-control addresses, matching MITRE technique T1102.001.
- Fake guest-complaint emails target hotel front desk and reservations staff.
- Links deliver archives with malicious LNK shortcuts disguised as JPG evidence.
- Shortcuts install Node.js, which runs EtherRAT or TONResolver.
- Both families resolve C2 addresses from Ethereum or TON blockchain data.
- Cofense links the activity to earlier Booking.com phishing with moderate confidence.
Full article594 words · extracted from gbhackers.com · click to collapse
Hackers are targeting hotels with fabricated guest complaints and negative reviews to distribute EtherRAT and TONResolver, two malware families that abuse public blockchains to locate their command-and-control infrastructure.
The activity appears to extend earlier Booking. com-themed phishing operations, although Cofense assesses that connection with moderate confidence.
Similar email templates and accommodation-sector targeting link the campaigns.
However, the newer attacks replace fake CAPTCHA instructions with downloadable files designed to exploit hotel employees’ obligation to investigate guest concerns.
Messages reach front-desk, reservations, and guest-relations personnel, presenting everything from dirty-room complaints to allegations of staff harassment and legal threats.
Some arrive as replies after an apparently legitimate conversation, adding credibility and pressure to review purported evidence.
Embedded links download an archive containing a malicious LNK shortcut masquerading as a JPG image and a dummy MP4 file.
Windows shortcuts normally point to files or applications, but these weaponized shortcuts execute instructions rather than display the promised photograph.
The dummy video changes size between downloads. Cofense believes this variation likely produces different archive hashes, weakening detection that depends exclusively on previously identified file fingerprints.
Executing the shortcut downloads a legitimate Node.js runtime, which subsequently runs either EtherRAT or TONResolver.
Cofense also assesses with moderate confidence that attackers use generative AI to produce varied messages.
That remains an analytical judgment rather than confirmed attribution, but the diversity of complaint narratives complicates detection based on repeated wording.
Both payloads use blockchain data as a directory for their current C2 destination, rather than relying on a fixed domain embedded in the malware.
Cofense Intelligence’s analysis describes campaigns, that turn routine customer correspondence into an infection pathway, using malicious Windows shortcuts disguised as photographic evidence.
Fake Guest Complaint Phishing
The blockchain supplies the address; the attacker-controlled server remains the operational communication endpoint.
EtherRAT queries an Ethereum smart contract through a public JSON-RPC endpoint.

A read request retrieves encoded data, which the malware decodes and deobfuscates into a domain or IP address. Operators can update the stored destination through transactions without redistributing the payload.
TONResolver follows the same principle using public TON APIs to retrieve data associated with a wallet or smart contract.
Cofense observed multiple destinations associated with each family, illustrating how operators rotate infrastructure while retaining the same on-chain reference.
Their shared Node.js execution model suggests possible common loader infrastructure, not definitive proof of a single operator.
Using different blockchains also diversifies resolution services: restricting Ethereum access alone would not address a payload consulting TON.
The approach aligns with MITRE ATT&CK’s Dead Drop Resolver technique, T1102.001, which describes legitimate services hosting pointers to secondary C2 infrastructure.
MITRE notes that such indirection improves operational resilience and can obscure backend infrastructure during malware analysis.
Blockchain records resist conventional removal requests, but the external C2 servers remain disruptable.
Domain blocking alone may therefore interrupt communication without eliminating an infection’s ability to discover replacement infrastructure.
The campaign also connects to Cofense’s earlier Booking.com-spoofing ClickFix analysis, where fake verification pages persuaded users to run clipboard-delivered commands.
Defenders should correlate suspicious shortcut execution, unexpected runtime deployment, and subsequent resolver traffic, rather than treating blockchain API requests as inherently malicious.
MITRE recommends enforcing external-service policies and detecting processes that retrieve obfuscated pointers to secondary servers.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.