Hackers Use Negative Hotel Reviews to Spread Malware That Hides C2 on Blockchain
Cofense says hotel staff are phished with fake complaints that deliver EtherRAT and TONResolver using blockchain C2.
Cofense reported that attackers email hotel front-desk and guest-relations staff with fake negative reviews and complaint links that lead to malware. Archives contain a Windows LNK shortcut disguised as a photo; opening it downloads Node.js and installs EtherRAT or TONResolver. EtherRAT reads an Ethereum smart contract over a public JSON-RPC service to recover its command-and-control address, while TONResolver uses a TON blockchain API, a method known as dead-drop resolving. Cofense assesses with moderate confidence that the activity continues earlier Booking.com phishing that delivered PureRAT or NetSupport Manager, and that generative AI may vary the email wording.
- Fake guest complaints lure hotel staff into opening malicious links.
- LNK files disguised as images download Node.js and a payload.
- EtherRAT resolves C2 from an Ethereum smart contract.
- TONResolver uses the TON blockchain for the same dead-drop method.
- Earlier related lures delivered PureRAT or NetSupport Manager.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | allres.southafricanorth.cloudapp.azure.com | rwayeast[.]cloudapp[.]azure[.]com EtherRAT C2 URL hxxps[://]allres[.]southafricanorth[.]cloudapp[.]azure[.]com EtherRAT C2 URL hxxps[://]synctimes[.]australiaeast |
| domain | amanohuguta.cfd | af0c02a0ab7ea6cd78de06507fc5dc2c1a5d9 TONResolver C2 domain amanohuguta[.]cfd TONResolver C2 domain hsaertyuoang34[.]sbs TONResolver C2 |
| domain | booking.com | ith moderate confidence that the activity continues earlier Booking.com phishing campaigns, although shared malware tools used by s |
| domain | dns1.southafricanorth.cloudapp.azure.com | xxps[://]lermontov-656idlop[.]com EtherRAT C2 URL hxxps[://]dns1[.]southafricanorth[.]cloudapp[.]azure[.]com EtherRAT C2 domain fdffofofofo4[.]com EtherRAT C2 U |
| domain | fdffofofofo4.com | outhafricanorth[.]cloudapp[.]azure[.]com EtherRAT C2 domain fdffofofofo4[.]com EtherRAT C2 URL hxxps[://]update[.]norwayeast[.]cloudapp[ |
| domain | gateway001kir.com | 1C349b03c79E348018a8391bD21C412E8 EtherRAT C2 URL hxxps[://]gateway001kir[.]com EtherRAT C2 URL hxxps[://]sslgateway001[.]com EtherRAT C2 |
Full article820 words · extracted from cybersecuritynews.com · click to collapse
Hackers are targeting hotels with fake guest complaints and negative reviews that lead staff to malware disguised as photographic evidence.
The campaign delivers EtherRAT or TONResolver, two malware families that use public blockchains to find their command and control servers instead of relying on a fixed address inside the malware.
The emails reach front desk, reservations, and guest relations teams, where handling customer concerns is part of daily work.
Messages describe dirty rooms, disputes with employees, or possible legal action. Links offer supposed photos, videos, or documents, turning pressure to protect a hotel’s reputation into a reason to open dangerous files.
Researchers from Cofense identified EtherRAT and TONResolver in these campaigns and detailed their findings in an October 7 report by intelligence analyst Kahng An.
They assess with moderate confidence that the activity continues earlier Booking.com phishing campaigns, although shared malware tools used by separate groups could also explain the similarities.
Hackers Use Negative Hotel Reviews
Earlier attacks used fake booking messages and ClickFix pages that asked staff to paste commands into the Windows Run window. Those campaigns commonly delivered PureRAT or NetSupport Manager.
Previous reporting on compromised hotel booking accounts shows how hotel infections can support wider fraud, but Cofense does not confirm that outcome here.
.webp)
The newer emails link to an archive containing a malicious Windows shortcut, or LNK file, disguised as a JPG image. Opening it runs code rather than showing a photograph.
The archive also includes a dummy MP4 file whose size changes with each download, likely producing different hashes that weaken fixed file signature checks.
The shortcut downloads Node.js, a legitimate environment for running JavaScript, and installs either malware family.
Both use this runtime. Cofense says this shared approach suggests a possible common loader, not proof of one operator. Researchers also assess with moderate confidence that attackers use generative AI to vary the wording of their emails.
How EtherRAT and TONResolver Find C2 Servers
EtherRAT reads an Ethereum smart contract through a public JSON-RPC service, using a request such as eth_call. It decodes the returned hexadecimal data and removes light masking to recover the current C2 domain or IP address.
Earlier coverage of EtherRAT blockchain hiding techniques explains this same design in other attacks, without establishing who runs this hotel campaign.
TONResolver follows the same basic process using a public TON blockchain API and data tied to a wallet or smart contract.
Reporting on TONResolver smart contract abuse previously described hotel phishing with similar delivery methods. The key distinction is which blockchain supplies the address, not whether the malware still needs an external command server.
.webp)
This approach is called blockchain dead drop resolving. The blockchain stores directions to C2 infrastructure; it is not itself the server issuing every command.
Operators can publish a new destination through a transaction, allowing existing infections to locate replacement servers without receiving a new malware file.
That weakens takedowns aimed only at domains or hosting accounts. Removing a server does not erase the blockchain record that points infected devices toward its replacement.
Public blockchain API requests can also resemble legitimate wallet traffic. Cofense notes that blocking Ethereum access alone may leave TON access available in campaigns using the other family.
Hotel teams should examine unexpected complaint links with the same care as other unsolicited messages, even when a sender threatens immediate consequences.
Cofense recommends training staff to spot malicious emails rather than relying only on fixed wording or hashes. The report also warns that public customer support, sales, and business development inboxes face similar risks.
Security teams should also investigate unexpected Node.js activity on hotel workstations and link endpoint findings with email evidence. A legitimate runtime or blockchain service should not make a suspicious download appear safe to staff automatically.
Indicators of compromise (IoCs):-
| Malware | Indicator type | Source value |
|---|---|---|
| EtherRAT | Ethereum contract | 0x277852e1C349b03c79E348018a8391bD21C412E8 |
| EtherRAT | C2 URL | hxxps[://]gateway001kir[.]com |
| EtherRAT | C2 URL | hxxps[://]sslgateway001[.]com |
| EtherRAT | C2 URL | hxxps[://]waygatterol002[.]com |
| EtherRAT | C2 URL | hxxps[://]lotus-vista-additions-joshua[.]trycloudflare[.]com |
| EtherRAT | C2 URL | hxxps[://]perrine90-deltajohnsons[.]com |
| EtherRAT | C2 URL | hxxps[://]kadmecnp-643laolmd[.]com |
| EtherRAT | C2 URL | hxxps[://]lermontov-656idlop[.]com |
| EtherRAT | C2 URL | hxxps[://]dns1[.]southafricanorth[.]cloudapp[.]azure[.]com |
| EtherRAT | C2 domain | fdffofofofo4[.]com |
| EtherRAT | C2 URL | hxxps[://]update[.]norwayeast[.]cloudapp[.]azure[.]com |
| EtherRAT | C2 URL | hxxps[://]allres[.]southafricanorth[.]cloudapp[.]azure[.]com |
| EtherRAT | C2 URL | hxxps[://]synctimes[.]australiaeast[.]cloudapp[.]azure[.]com |
| EtherRAT | C2 URL | hxxps[://]opencode-setup-al[.]com |
| EtherRAT | C2 URL | hxxps[://]luxmaxing[.]southafricanorth[.]cloudapp[.]azure[.]com |
| TONResolver | TON contract | 0:c66119f0e5635c4380441d7a79baf0c02a0ab7ea6cd78de06507fc5dc2c1a5d9 |
| TONResolver | C2 domain | amanohuguta[.]cfd |
| TONResolver | C2 domain | hsaertyuoang34[.]sbs |
| TONResolver | C2 domain | zloapobikahy23[.]bond |
| TONResolver | C2 domain | tonajukbhuakpo2[.]shop |
| TONResolver | C2 domain | njzlopghznkamkl[.]cfd |
| TONResolver | C2 domain | nuypoiaklber[.]lol |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.