By: Kahng An, Intelligence Team
Cofense Intelligence has been tracking a series of email campaigns that target the accommodation industry with fake guest complaints or reviews that deliver blockchain technology-abusing malware. These emails appear to likely be a continuation of a prior series of predominantly Booking.com-spoofing emails that were seen delivering various remote access trojans (RAT) via ClickFix fake CAPTCHA websites. Cofense Intelligence assesses this with moderate confidence based on similarities in email templates and the targeted industry. This report is a broad overview of these campaigns’ email templates, how the Ethereum and TON blockchains are being abused, and the similarities between the EtherRAT and TONResolver malware payloads found in these campaigns.
Key Takeaways
- Threat actors are targeting the accommodation industry with fake guest complaints, reviews, or inquiry related emails that lead recipients to a malicious LNK shortcut file purporting to be an image related to the email.
- LNK shortcut files, also known as .lnk files, are legitimately used as shortcuts to files or programs, but threat actors can abuse these files to run programs or script payloads.
- While the campaign attack chain appears to consistently deliver this LNK shortcut file that masquerades as an image file, the exact theme of the emails varies drastically, ranging from simple accommodation related questions to legal threats against the recipient.
- Two malware families, EtherRAT and TONResolver, are being delivered by this campaign. Both resolve their command and control (C2) infrastructure by reading data stored on a public blockchain instead of relying on a hardcoded domain or IP address.
- Storing C2 domains and IP addresses on a public blockchain lets threat actors rotate C2 infrastructure by submitting a small transaction instead of registering a new domain, and it makes conventional domain and IP takedown requests largely ineffective because blockchain data cannot be removed by a hosting provider, domain registrar, or a single law enforcement request.
- Cofense Intelligence assesses with moderate confidence that this activity is a continuation of earlier Booking.com-spoofing, travel assistance-themed campaigns that delivered more conventional RATs like PureRAT, based on overlapping lure themes and targeted industry sector.
Email Campaign Overview
This campaign uses fake guest complaint and negative review emails to convince recipients to run some kind of malware payload. While earlier campaigns relied on ClickFix fake CAPTCHAs on Booking.com-spoofing sites to deliver malicious scripts that download RATs (most notably PureRAT), the current campaigns attempt to convince potential victims that an LNK shortcut file masquerading as a JPG image file is something that needs to be reviewed by hotel staff. These LNK shortcut files lead to EtherRAT or TONResolver.
Prior Booking.com-Spoofing Campaigns
Cofense Intelligence has previously tracked a series of Booking.com-spoofing, travel assistance-themed campaigns that were most notable for using ClickFix fake CAPTCHAs that deliver malicious scripts to the clipboard in order to deliver various RATs (typically PureRAT or NetSupport Manager RAT) and/or information stealers. These emails typically impersonated a guest reservation, payment confirmation, or Booking.com-related system message and included a link that led to a fake Booking.com site with the ClickFix payload. Because hotel staff routinely handle inbound messages from online travel agencies like Booking.com or from guests directly as a normal part of daily operations, this email lure theme has historically been effective at blending in with legitimate emails.

Figure 1: A sample Booking.com-spoofing email that delivers malware via a ClickFix fake CAPTCHA site.
These prior campaigns were notable for relying on ClickFix fake CAPTCHAs, a social-engineering technique that convinces a victim to execute a malicious script that masquerades as a CAPTCHA verification code. In these campaigns, the embedded links lead to a fake Booking.com site styled as a routine CAPTCHA verification. However, the site instructs the victim to paste the malicious “verification code” into the Windows Run dialog via the Win + R shortcut. These ClickFix sites automatically deliver the malicious script payload to the clipboard and attempt to get a victim to run a malicious script on their own. For more details on this specific campaign type, refer to Cofense Intelligence’s previous Strategic Analysis report ClickFix Delivers Malware in Booking.com-Spoofing Campaigns.
Current Fake Guest Complaint and Review Email Lures
The newer campaigns that are the focus of this report shift the email lures away from Booking.com-spoofing emails and towards fabricated complaints, negative reviews, or inquiries sent directly from purported hotel guests. These emails are typically addressed to a hotel's front desk, reservations, or guest relations staff and claim to need the recipient to review a photo or some document. The strength of the email lures used in this campaign is based on how wide \a range of fake guest stories or needs are presented in the samples that have been reviewed by Cofense Intelligence. These lures range from relatively benign messages reporting hotel room conditions to ones with highly elaborate stories about hotel staff harassing guests. As a result, these emails also vary widely in their wording and format from one message to the next. Cofense Intelligence assesses with moderate confidence that the threat actors are using generative AI to write a unique version of each email, making them harder for traditional email security tools to catch.

Figure 2: A recent email that delivers EtherRAT via a link purporting to have evidence of an unclean room.

Figure 3: A recent email that delivers TONResolver via a link purporting to have a video of an altercation with hotel staff.
The embedded links found in these emails lead to an archive file that contains an LNK shortcut that has a mismatched .JPG file extension. The archive also contains a dummy .MP4 file which varies in file size every time it is downloaded. The threat actors likely use this to generate different file hashes per download to reduce the effectiveness of static file hash-based detections. Once the LNK file is run, it downloads a NodeJS runtime environment (a legitimate tool used to run JavaScript as a standalone piece of software on a computer) and, depending on the specific campaign, installs either EtherRAT or TONResolver.
Malware Overview
The LNK files delivered through this campaign ultimately install one of two related malware families, EtherRAT or TONResolver. While the two families differ in the specific blockchain technology they rely on, they share the same core design principle of querying a public blockchain API at runtime to resolve its current C2 address instead of using a hardcoded domain or IP address. This technique works because cryptocurrency wallets and smart contracts (scripts that run on a blockchain) can both store arbitrary data on a blockchain, which can then be updated with cryptocurrency transactions and retrieved via publicly accessible APIs. Notably, both malware families are run via a NodeJS runtime environment, which suggests a possible shared set of loader infrastructure that is used to retrieve different C2s from different blockchains. Threat actors likely use various blockchains to diversify by using multiple different public APIs and different sets of infrastructure to have more options against simple traffic filtering or blocking. If an organization blocks access to APIs for the Ethereum blockchain, the threat actors may be able to still access the TON blockchain.
EtherRAT
EtherRAT queries the address of a smart contract on the Ethereum blockchain via an Ethereum JSON-RPC endpoint, effectively an API that can retrieve data from the blockchain, to retrieve its C2 address. At runtime, the malware sends a read request, like an eth_call request, to a public Ethereum JSON-RPC endpoint in order to read a specific storage slot or emitted event from the contract.
The returned value, once decoded from hexadecimal and lightly deobfuscated, resolves to the current C2 domain or IP address that EtherRAT should beacon to. Because the contract's stored value can be updated at any time by the threat actor for a small transaction fee, EtherRAT’s operators can rotate C2 infrastructure without needing to change or redistribute the malware.
For example, the Ethereum smart contract 0x277852e1C349b03c79E348018a8391bD21C412E8 from ATR 422147 is associated with the following C2 addresses, which have been updated over time via multiple different transactions.
hxxps[://]gateway001kir[.]com hxxps[://]sslgateway001[.]com hxxps[://]waygatterol002[.]com hxxps[://]lotus-vista-additions-joshua[.]trycloudflare[.]com hxxps[://]perrine90-deltajohnsons[.]com hxxps[://]kadmecnp-643laolmd[.]com hxxps[://]lermontov-656idlop[.]com hxxps[://]dns1[.]southafricanorth[.]cloudapp[.]azure[.]com fdffofofofo4[.]com hxxps[://]update[.]norwayeast[.]cloudapp[.]azure[.]com hxxps[://]allres[.]southafricanorth[.]cloudapp[.]azure[.]com hxxps[://]synctimes[.]australiaeast[.]cloudapp[.]azure[.]com hxxps[://]opencode-setup-al[.]com hxxps[://]luxmaxing[.]southafricanorth[.]cloudapp[.]azure[.]com |
TONResolver
TONResolver is conceptually similar to EtherRAT, but with the TON blockchain instead of Ethereum. The same general principles still apply, but TONResolver queries a public TON API endpoint to read data associated with a specific wallet address or smart contract. This data can include arbitrary text that is used to store an encoded C2 address in the same way the Ethereum smart contract is abused by EtherRAT.
For example, the TON smart contract address 0:c66119f0e5635c4380441d7a79baf0c02a0ab7ea6cd78de06507fc5dc2c1a5d9 from ATR 422158 is associated with the following C2 addresses which have been updated over time via multiple different transactions.
amanohuguta[.]cfd hsaertyuoang34[.]sbs zloapobikahy23[.]bond tonajukbhuakpo2[.]shop njzlopghznkamkl[.]cfd nuypoiaklber[.]lol |
Blockchain-Based Command and Control
The use of a blockchain to resolve C2 infrastructure, also known as blockchain-based dead drop resolving, is a novel technique to create more persistent ways of providing updated C2s to infected hosts. While dead drop resolving is not necessarily a new concept altogether (the MITRE ATT&CK framework has tracked this tactic since March 2020 as T1102.001), using messages within a blockchain ledger is a meaningful evolution beyond the kinds of legitimate platform abuse that have been previously seen with free hosting providers, dynamic DNS, and code repositories. Strategically, threat actors may find this tactic worthwhile because it challenges traditional infrastructure tracking and security defenses in a few different ways.
- Takedown resilience: A threat actor’s domain, hosting server, or account on a legitimate platform can be suspended by a registrar or service provider, but a value written to a public blockchain cannot be deleted and is not owned by any single individual, organization, or corporate entity. Malware that attempts to look up an address can keep resolving the same address to receive a new C2 whenever the threat actor needs to update it.
- Very low cost: Changing C2 domains costs the threat actor a small transaction fee to put the new domain as part of an on-chain transaction.
- Traffic that blends in: Requests to public blockchain APIs are not necessarily malicious on their own and are difficult to distinguish from the legitimate traffic generated by cryptocurrency wallets and decentralized applications.
Compared to other methods of dead drop resolution, such as social media comments, pastebin sites, or Telegram channel descriptions, blockchain dead drops are both more resilient and deceptive while being as effective.
Conclusions
Threat actors targeting the hotel and travel accommodation industry have shifted from Booking.com-spoofing lures to more confrontational fake guest complaint and negative review lures that are sent directly to a specific hotel’s email address. While these previous Booking.com-spoofing lures often used similar themes about reservation requests, payment inquiries, or complaints about staff or facilities, these newer emails are notable for being more confrontational and sometimes being sent as replies within email threads after starting a legitimate conversation. Additionally, the PureRAT samples that were most strongly associated with the prior campaign attack chain have been replaced with EtherRAT and TONResolver, which look up their C2 domains against a public blockchain, allowing threat actors to rotate C2 infrastructure cheaply and making conventional domain or IP takedown requests largely ineffective on their own. Persistent infections can continue to query the same cryptocurrency address that the threat actor uses to store new C2 locations, allowing infected hosts to receive a new C2 whenever the threat actor decides to change domains.
Because of the similar email lure themes targeted at the accommodation industry and the relative timing between ClickFix-based Booking.com-spoofing campaigns falling off in volume before the first TONResolver sample seen by Cofense Intelligence, Cofense Intelligence assesses with moderate confidence that these EtherRAT and TONResolver campaigns stem from the same or closely affiliated threat actors as the earlier Booking.com-themed campaigns. However, Cofense Intelligence cannot fully rule out that this campaign attack chain could be a shared malware and email template kit that is used independently by multiple independent threat actors.
Mitigations
While this campaign targets the travel accommodation industry specifically, enterprises outside of this specific industry sector can be targeted with equally deceptive email lures that come through public facing email addresses like customer support, business development, or sales email addresses. Emails in this campaign are difficult to filter through traditional security detections that rely on static indicators because the exact phrasing of the lures can vary wildly between emails. These kinds of unsolicited complaint or negative review emails tend to provoke urgency by threatening immediate consequences, hoping to catch the recipient off-guard. As a result, a better approach is to train employees to recognize common signs of malicious emails and treat all emails with the same level of scrutiny when reviewing them for malicious indicators.