Hackers are establishing their persistence in hospitality and hotels by posing as guests with poisoned ZIP files, but no one knows what their plan is.



  • Microsoft Threat Intelligence warns of phishing campaign targeting hotel staff in Europe and Asia with emails related to guest complaints
  • Attackers abuse services like Calendly and Google redirects to bypass authentication checks, delivering photo-themed ZIP files that install a persistent Node.js implant.
  • The malware disables Defender, runs C2 beacons, collects system information, and forces shutdowns; Signs include unusual PowerShell activity, Node.js execution, and suspicious registry entries

Hackers are gaining a foothold in hotels and hospitality organizations across Europe and Asia, but no one really knows why, at least not yet.

This is according to Microsoft Threat Intelligence, who recently published a new report saying that it has been tracking an active phishing campaign since April. In this campaign, anonymous attackers target front desk, front desk, and reservation staff with emails about guest complaints, room conditions, bed bug infestations, reservation inquiries, and the like.

Leave a Comment

Your email address will not be published. Required fields are marked *