# Microsoft Alerts Hotels to Active Phishing Campaign Deploying Node.js-Based TonRAT Implant


A sophisticated phishing campaign has been actively targeting hotel and hospitality organizations across Europe and Asia since April 2026, Microsoft warns, using deceptively simple photo-themed ZIP files as a delivery mechanism for a persistent Node.js-based remote access trojan. The operation, which routes emails through legitimate infrastructure providers to bypass authentication checks, represents a concerning evolution in how threat actors abuse trusted platforms to gain footholds in hospitality networks.


## The Campaign at a Glance


The attack begins with phishing emails bearing the display name "Booking Manager (via Calendly)" and subject lines that reference common hotel operational pain points—guest complaints, bedbug infestations, room maintenance inquiries, health inspections, and stay reviews. The lures appear in Japanese, Danish, and Dutch, with Japanese being the most prevalent language variant.


The targeting is indiscriminate. Subject lines omit specific recipient names or property identifiers, indicating high-volume, list-driven distribution rather than tailored spear phishing. However, the psychological pressure is calibrated: each message invokes scenarios—cleanliness violations, final warnings, pending inspections—that create urgency for front-desk staff to act immediately.


Geography: Europe and Asia (specific countries not disclosed by Microsoft)

Duration: Active since April 2026

Primary Language: Japanese

Targeted Role: Front-desk and hospitality operations staff

Attribution: Unknown threat actor; activity not linked to known groups


## The Delivery Chain: "Authentication Laundering" in Action


What distinguishes this campaign is not the social engineering—hotel phishing is recurring—but the sophistication of the delivery mechanism. Microsoft describes the technique as authentication laundering: the misuse of legitimate, trusted email providers to pass email authentication checks while obscuring malicious intent.


### How the Attack Unfolds


| Stage | Mechanism | Purpose |

|-------|-----------|---------|

| Email Origin | Calendly email notification system | Passes SPF, DKIM, DMARC checks |

| First Redirect | Calendly link to share.google | Maintains trusted domain chain |

| Second Redirect | Google URL redirect service | Continues trust chain |

| Final Destination | Freshly registered .cfd domain (Cloudflare-fronted) | Hosts malicious download |

| Anti-Analysis | Turnstile CAPTCHA challenge | Blocks automated analysis |

| Payload Download | photo-<numbers>.zip | Contains malicious shortcut |


The emails originate from Calendly's notification system, which is legitimate infrastructure. Because the messages genuinely pass through Calendly's authorized servers, they pass SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) checks. Email authentication systems confirm only that the sender is authorized to send from Calendly—they say nothing about the message content or intent.


From there, a multi-hop chain routes victims through Google's URL redirect infrastructure (share.google) before landing on a freshly registered Cloudflare-backed .cfd domain. The inclusion of a Turnstile CAPTCHA challenge serves dual purposes: it appears as a legitimate verification step to users and simultaneously defeats automated analysis by requiring human interaction.


## The Payload: Node.js as a Persistence Mechanism


The downloaded ZIP file contains a deceptive shortcut file masquerading as an image:


  • First wave: IMG-<numbers>.png.lnk
  • Second wave: PHOTO-<numbers>.png.lnk

  • Opening the shortcut executes PowerShell. The script employs BigInt arithmetic to decode a hidden download URL—a technique that obscures the payload location and complicates reverse engineering. Once decoded, the script downloads and executes a .ps1 file, which then retrieves a legitimate Node.js v24.13.0 runtime from nodejs.org.


    The use of Node.js is significant. By dropping a user-space Node.js installation—rather than relying on a system-wide installation—the operators achieve several objectives:


    1. Minimal environmental dependencies — No system-level Node.js install required

    2. Defense evasion — The presence of a Node.js runtime in %APPDATA% may evade detection systems tuned to flag system-level installs

    3. Deniability — Node.js can appear as a legitimate development tool

    4. Portability — The runtime and implant can be moved or reinstalled easily


    The implant payload is identified as TonRAT, a remote access trojan that leverages unconventional command-and-control mechanisms.


    ## Command and Control: Blockchain-Based Domain Resolution


    TonRAT uses the TON (The Open Network) blockchain API to resolve its command-and-control domains dynamically. Rather than communicating with fixed C2 servers, the implant queries the blockchain to retrieve current C2 addresses. This approach renders static blocklists ineffective and significantly complicates network-based detection and blocking.


    After establishing contact, the implant opens an encrypted WebSocket channel to communicate securely with the attacker's infrastructure. Beaconing occurs over non-standard ports:


  • 8443, 8445, 8453 (variations of common HTTPS ports)
  • 5555
  • 56001–56003 (high-number range to evade shallow port filtering)

  • Some compromised hosts exhibited additional behaviors:


  • Headless browser automation — Using --headless --no-sandbox flags, likely for automated credential harvesting or account takeover
  • Geolocation checks — Queries to ip-api.com to confirm the victim's location
  • Forced shutdown — Execution of cmd /c shutdown -s -t 0 to terminate the host (potentially to cover tracks or force a restart into a modified system state)

  • ## Current Impact and Unknowns


    Microsoft has not reported:

  • Confirmed data theft or exfiltration
  • Ransomware deployment
  • Named victim organizations

  • This ambiguity is troubling. The access is durable (Node.js and persistence mechanisms remain active), the cleanup is complex (multiple removal points required), and the final objective remains unknown. This suggests the infrastructure may be maintained for future operations—reconnaissance, lateral movement, or deployment of secondary payloads.


    ## Remediation and Detection


    Full remediation requires addressing both persistence mechanisms:


    1. Remove RunOnce registry entry pointing to %ProgramData%

    2. Remove Node.js Run key pointing to AppData\Local\Nodejs

    3. Delete the Node.js runtime and associated .js files under AppData\Local\Nodejs


    Deletion of only one entry leaves the other functional, allowing re-infection.


    Priority systems for investigation:

  • Front-desk machines
  • Reservation and booking systems
  • Guest management systems

  • Network defenders should monitor for:

  • .png.lnk file downloads
  • PowerShell decoding/execution of URLs
  • Node.js process launches from user AppData directories
  • Outbound connections to TON blockchain APIs
  • Beaconing on non-standard ports (8443, 8445, 8453, 5555, 56001–56003)

  • ## HackWire Analysis


    This campaign exemplifies a troubling evolution in phishing sophistication: the repurposing of legitimate, authentication-passing infrastructure to defeat email security controls. Calendly and Google are not compromised; rather, their legitimate notification systems are weaponized as unwitting allies in the attack chain. Organizations that rely solely on email gateway scanning and SPF/DKIM/DMARC validation will miss these messages entirely.


    The use of Node.js as a persistence mechanism is equally telling. Rather than relying on traditional Windows malware or script execution, TonRAT arrives bundled with a legitimate, signed runtime. This approach is harder to detect because Node.js in a user directory can plausibly belong to a developer, and the Windows Defender exclusions many developers use (to avoid false positives during development) become an inadvertent defense bypass. The attackers have weaponized the same assumptions that secure development practices rely upon.


    Most concerning is the unknown end goal. In recorded phishing campaigns with clear objectives—credential theft, ransomware deployment, data exfiltration—the malware landscape is predictable. But when a threat actor establishes durable access (Node.js + multiple persistence points), maintains it quietly, and hasn't revealed their hand, the implication is reconnaissance or infrastructure staging for something bigger. This could be a precursor to targeted ransomware, credential harvesting at scale, or network reconnaissance before lateral movement into payment systems, booking backends, or guest databases.


    Hotels should treat this as a wake-up call. Front-desk and operations staff are not security analysts; they are targets precisely because they handle urgent, reputation-damaging issues daily. The phishing lures exploit this reality. Organizations in hospitality cannot solely defend by user education—they must segment front-desk systems, enforce application-level controls, and assume some percentage of staff will click. — HackWire Editorial


    ## Related Coverage


  • Read more in our [Phishing & Social Engineering](https://www.hackwire.news/category/phishing) coverage
  • Cross-reference with [Malware](https://www.hackwire.news/category/malware) and [Threats](https://www.hackwire.news/category/threats)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)