Hackers Use Negative Hotel Reviews to Spread Malware That Hides C2 on Blockchain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers are targeting hotels with fake guest complaints and negative reviews that lead staff to malware disguised as photographic evidence.

The campaign delivers EtherRAT or TONResolver, two malware families that use public blockchains to find their command and control servers instead of relying on a fixed address inside the malware.

The emails reach front desk, reservations, and guest relations teams, where handling customer concerns is part of daily work.

Messages describe dirty rooms, disputes with employees, or possible legal action. Links offer supposed photos, videos, or documents, turning pressure to protect a hotel’s reputation into a reason to open dangerous files.

Researchers from Cofense identified EtherRAT and TONResolver in these campaigns and detailed their findings in an October 7 report by intelligence analyst Kahng An.

They assess with moderate confidence that the activity continues earlier Booking.com phishing campaigns, although shared malware tools used by separate groups could also explain the similarities.

Hackers Use Negative Hotel Reviews

Earlier attacks used fake booking messages and ClickFix pages that asked staff to paste commands into the Windows Run window. Those campaigns commonly delivered PureRAT or NetSupport Manager.

Previous reporting on compromised hotel booking accounts shows how hotel infections can support wider fraud, but Cofense does not confirm that outcome here.

A sample Booking.com-spoofing email (Source - Cofense)
A sample Booking.com-spoofing email (Source – Cofense)

The newer emails link to an archive containing a malicious Windows shortcut, or LNK file, disguised as a JPG image. Opening it runs code rather than showing a photograph.

The archive also includes a dummy MP4 file whose size changes with each download, likely producing different hashes that weaken fixed file signature checks.

The shortcut downloads Node.js, a legitimate environment for running JavaScript, and installs either malware family.

Both use this runtime. Cofense says this shared approach suggests a possible common loader, not proof of one operator. Researchers also assess with moderate confidence that attackers use generative AI to vary the wording of their emails.

How EtherRAT and TONResolver Find C2 Servers

EtherRAT reads an Ethereum smart contract through a public JSON-RPC service, using a request such as eth_call. It decodes the returned hexadecimal data and removes light masking to recover the current C2 domain or IP address.

Earlier coverage of EtherRAT blockchain hiding techniques explains this same design in other attacks, without establishing who runs this hotel campaign.

TONResolver follows the same basic process using a public TON blockchain API and data tied to a wallet or smart contract.

Reporting on TONResolver smart contract abuse previously described hotel phishing with similar delivery methods. The key distinction is which blockchain supplies the address, not whether the malware still needs an external command server.

A recent email that delivers TONResolver (Source - Cofense)
A recent email that delivers TONResolver (Source – Cofense)

This approach is called blockchain dead drop resolving. The blockchain stores directions to C2 infrastructure; it is not itself the server issuing every command.

Operators can publish a new destination through a transaction, allowing existing infections to locate replacement servers without receiving a new malware file.

That weakens takedowns aimed only at domains or hosting accounts. Removing a server does not erase the blockchain record that points infected devices toward its replacement.

Public blockchain API requests can also resemble legitimate wallet traffic. Cofense notes that blocking Ethereum access alone may leave TON access available in campaigns using the other family.

Hotel teams should examine unexpected complaint links with the same care as other unsolicited messages, even when a sender threatens immediate consequences.

Cofense recommends training staff to spot malicious emails rather than relying only on fixed wording or hashes. The report also warns that public customer support, sales, and business development inboxes face similar risks.

Security teams should also investigate unexpected Node.js activity on hotel workstations and link endpoint findings with email evidence. A legitimate runtime or blockchain service should not make a suspicious download appear safe to staff automatically.

Indicators of compromise (IoCs):-

Malware Indicator type Source value
EtherRAT Ethereum contract 0x277852e1C349b03c79E348018a8391bD21C412E8
EtherRAT C2 URL hxxps[://]gateway001kir[.]com
EtherRAT C2 URL hxxps[://]sslgateway001[.]com
EtherRAT C2 URL hxxps[://]waygatterol002[.]com
EtherRAT C2 URL hxxps[://]lotus-vista-additions-joshua[.]trycloudflare[.]com
EtherRAT C2 URL hxxps[://]perrine90-deltajohnsons[.]com
EtherRAT C2 URL hxxps[://]kadmecnp-643laolmd[.]com
EtherRAT C2 URL hxxps[://]lermontov-656idlop[.]com
EtherRAT C2 URL hxxps[://]dns1[.]southafricanorth[.]cloudapp[.]azure[.]com
EtherRAT C2 domain fdffofofofo4[.]com
EtherRAT C2 URL hxxps[://]update[.]norwayeast[.]cloudapp[.]azure[.]com
EtherRAT C2 URL hxxps[://]allres[.]southafricanorth[.]cloudapp[.]azure[.]com
EtherRAT C2 URL hxxps[://]synctimes[.]australiaeast[.]cloudapp[.]azure[.]com
EtherRAT C2 URL hxxps[://]opencode-setup-al[.]com
EtherRAT C2 URL hxxps[://]luxmaxing[.]southafricanorth[.]cloudapp[.]azure[.]com
TONResolver TON contract 0:c66119f0e5635c4380441d7a79baf0c02a0ab7ea6cd78de06507fc5dc2c1a5d9
TONResolver C2 domain amanohuguta[.]cfd
TONResolver C2 domain hsaertyuoang34[.]sbs
TONResolver C2 domain zloapobikahy23[.]bond
TONResolver C2 domain tonajukbhuakpo2[.]shop
TONResolver C2 domain njzlopghznkamkl[.]cfd
TONResolver C2 domain nuypoiaklber[.]lol

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Hackers Use Negative Hotel Reviews to Spread Malware That Hides C2 on Blockchain appeared first on Cyber Security News.