# Microsoft Alerts Hotels to Active Phishing Campaign Deploying Node.js-Based TonRAT Implant
A sophisticated phishing campaign has been actively targeting hotel and hospitality organizations across Europe and Asia since April 2026, Microsoft warns, using deceptively simple photo-themed ZIP files as a delivery mechanism for a persistent Node.js-based remote access trojan. The operation, which routes emails through legitimate infrastructure providers to bypass authentication checks, represents a concerning evolution in how threat actors abuse trusted platforms to gain footholds in hospitality networks.
## The Campaign at a Glance
The attack begins with phishing emails bearing the display name "Booking Manager (via Calendly)" and subject lines that reference common hotel operational pain points—guest complaints, bedbug infestations, room maintenance inquiries, health inspections, and stay reviews. The lures appear in Japanese, Danish, and Dutch, with Japanese being the most prevalent language variant.
The targeting is indiscriminate. Subject lines omit specific recipient names or property identifiers, indicating high-volume, list-driven distribution rather than tailored spear phishing. However, the psychological pressure is calibrated: each message invokes scenarios—cleanliness violations, final warnings, pending inspections—that create urgency for front-desk staff to act immediately.
Geography: Europe and Asia (specific countries not disclosed by Microsoft)
Duration: Active since April 2026
Primary Language: Japanese
Targeted Role: Front-desk and hospitality operations staff
Attribution: Unknown threat actor; activity not linked to known groups
## The Delivery Chain: "Authentication Laundering" in Action
What distinguishes this campaign is not the social engineering—hotel phishing is recurring—but the sophistication of the delivery mechanism. Microsoft describes the technique as authentication laundering: the misuse of legitimate, trusted email providers to pass email authentication checks while obscuring malicious intent.
### How the Attack Unfolds
| Stage | Mechanism | Purpose |
|-------|-----------|---------|
| Email Origin | Calendly email notification system | Passes SPF, DKIM, DMARC checks |
| First Redirect | Calendly link to share.google | Maintains trusted domain chain |
| Second Redirect | Google URL redirect service | Continues trust chain |
| Final Destination | Freshly registered .cfd domain (Cloudflare-fronted) | Hosts malicious download |
| Anti-Analysis | Turnstile CAPTCHA challenge | Blocks automated analysis |
| Payload Download | photo-<numbers>.zip | Contains malicious shortcut |
The emails originate from Calendly's notification system, which is legitimate infrastructure. Because the messages genuinely pass through Calendly's authorized servers, they pass SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) checks. Email authentication systems confirm only that the sender is authorized to send from Calendly—they say nothing about the message content or intent.
From there, a multi-hop chain routes victims through Google's URL redirect infrastructure (share.google) before landing on a freshly registered Cloudflare-backed .cfd domain. The inclusion of a Turnstile CAPTCHA challenge serves dual purposes: it appears as a legitimate verification step to users and simultaneously defeats automated analysis by requiring human interaction.
## The Payload: Node.js as a Persistence Mechanism
The downloaded ZIP file contains a deceptive shortcut file masquerading as an image:
IMG-<numbers>.png.lnk PHOTO-<numbers>.png.lnkOpening the shortcut executes PowerShell. The script employs BigInt arithmetic to decode a hidden download URL—a technique that obscures the payload location and complicates reverse engineering. Once decoded, the script downloads and executes a .ps1 file, which then retrieves a legitimate Node.js v24.13.0 runtime from nodejs.org.
The use of Node.js is significant. By dropping a user-space Node.js installation—rather than relying on a system-wide installation—the operators achieve several objectives:
1. Minimal environmental dependencies — No system-level Node.js install required
2. Defense evasion — The presence of a Node.js runtime in %APPDATA% may evade detection systems tuned to flag system-level installs
3. Deniability — Node.js can appear as a legitimate development tool
4. Portability — The runtime and implant can be moved or reinstalled easily
The implant payload is identified as TonRAT, a remote access trojan that leverages unconventional command-and-control mechanisms.
## Command and Control: Blockchain-Based Domain Resolution
TonRAT uses the TON (The Open Network) blockchain API to resolve its command-and-control domains dynamically. Rather than communicating with fixed C2 servers, the implant queries the blockchain to retrieve current C2 addresses. This approach renders static blocklists ineffective and significantly complicates network-based detection and blocking.
After establishing contact, the implant opens an encrypted WebSocket channel to communicate securely with the attacker's infrastructure. Beaconing occurs over non-standard ports:
Some compromised hosts exhibited additional behaviors:
--headless --no-sandbox flags, likely for automated credential harvesting or account takeovercmd /c shutdown -s -t 0 to terminate the host (potentially to cover tracks or force a restart into a modified system state)## Current Impact and Unknowns
Microsoft has not reported:
This ambiguity is troubling. The access is durable (Node.js and persistence mechanisms remain active), the cleanup is complex (multiple removal points required), and the final objective remains unknown. This suggests the infrastructure may be maintained for future operations—reconnaissance, lateral movement, or deployment of secondary payloads.
## Remediation and Detection
Full remediation requires addressing both persistence mechanisms:
1. Remove RunOnce registry entry pointing to %ProgramData%
2. Remove Node.js Run key pointing to AppData\Local\Nodejs
3. Delete the Node.js runtime and associated .js files under AppData\Local\Nodejs
Deletion of only one entry leaves the other functional, allowing re-infection.
Priority systems for investigation:
Network defenders should monitor for:
.png.lnk file downloads ## HackWire Analysis
This campaign exemplifies a troubling evolution in phishing sophistication: the repurposing of legitimate, authentication-passing infrastructure to defeat email security controls. Calendly and Google are not compromised; rather, their legitimate notification systems are weaponized as unwitting allies in the attack chain. Organizations that rely solely on email gateway scanning and SPF/DKIM/DMARC validation will miss these messages entirely.
The use of Node.js as a persistence mechanism is equally telling. Rather than relying on traditional Windows malware or script execution, TonRAT arrives bundled with a legitimate, signed runtime. This approach is harder to detect because Node.js in a user directory can plausibly belong to a developer, and the Windows Defender exclusions many developers use (to avoid false positives during development) become an inadvertent defense bypass. The attackers have weaponized the same assumptions that secure development practices rely upon.
Most concerning is the unknown end goal. In recorded phishing campaigns with clear objectives—credential theft, ransomware deployment, data exfiltration—the malware landscape is predictable. But when a threat actor establishes durable access (Node.js + multiple persistence points), maintains it quietly, and hasn't revealed their hand, the implication is reconnaissance or infrastructure staging for something bigger. This could be a precursor to targeted ransomware, credential harvesting at scale, or network reconnaissance before lateral movement into payment systems, booking backends, or guest databases.
Hotels should treat this as a wake-up call. Front-desk and operations staff are not security analysts; they are targets precisely because they handle urgent, reputation-damaging issues daily. The phishing lures exploit this reality. Organizations in hospitality cannot solely defend by user education—they must segment front-desk systems, enforce application-level controls, and assume some percentage of staff will click. — HackWire Editorial
## Related Coverage