Hackers Use Fake Hotel Reviews to Deliver Blockchain-Hidden Malware
Threat actors are targeting hotels with phishing emails containing fake negative reviews, leading staff to download malware that uses public blockchains for command and control.

Cybercriminals are employing a novel phishing strategy that preys on hotel staff's diligence in handling customer complaints. The attackers send emails containing fabricated negative reviews and fake guest complaints, often referencing issues like dirty rooms or employee disputes. These messages are designed to pressure hotel employees into opening attached files, which are actually malicious payloads.
The malware families identified in these campaigns are EtherRAT and TONResolver. What makes these threats particularly challenging to combat is their use of public blockchains, such as Ethereum and TON, as a "dead drop" mechanism to locate their command and control (C2) servers. Instead of embedding a fixed C2 address directly within the malware, which could be easily blocked, these tools query blockchain smart contracts or APIs to retrieve the current server location.
Researchers from Cofense detailed these findings, noting that the campaign's delivery method involves malicious LNK (shortcut) files disguised as image files (JPG). When executed, these LNK files download and run Node.js, a legitimate JavaScript runtime environment, which then facilitates the execution of either EtherRAT or TONResolver. The attackers also reportedly use dummy MP4 files within the archive to alter file hashes, further evading static signature-based detection.
Both EtherRAT and TONResolver leverage the blockchain "dead drop" technique. EtherRAT queries an Ethereum smart contract via a public JSON-RPC service, decodes the returned data, and extracts the C2 server's IP address or domain. Similarly, TONResolver uses a public TON blockchain API to achieve the same objective. This method allows attackers to change their C2 infrastructure without needing to update the malware on infected systems, making takedowns significantly more difficult.
While the specific threat actor behind this hotel-focused campaign remains unconfirmed, Cofense assesses with moderate confidence that it may be a continuation of earlier phishing campaigns targeting Booking.com. However, the use of shared malware tools by different groups could also explain the similarities. Previous attacks using similar phishing lures delivered different malware like PureRAT or NetSupport Manager.
The use of generative AI to vary email wording is also suspected, adding another layer of sophistication to the phishing attempts. This allows attackers to craft more convincing and personalized messages, increasing the likelihood of success.
To mitigate this threat, Cofense recommends robust security awareness training for hotel staff, emphasizing the need to scrutinize unexpected complaint links and unsolicited messages, regardless of the perceived urgency. Technical defenses should include monitoring for unusual Node.js activity on workstations and correlating endpoint alerts with email evidence. Blocking access to specific blockchain APIs could be considered, though attackers may pivot to other blockchains or alternative C2 methods.
This campaign highlights a growing trend of attackers using sophisticated techniques to obscure their infrastructure and exploit human trust. The reliance on legitimate tools like Node.js and the innovative use of public blockchains for C2 demonstrate the evolving tactics, techniques, and procedures (TTPs) employed by modern threat actors.