Fake Hotel Guest Complaints Deliver EtherRAT and TONResolver via Blockchain-Based C2

· Original article ↗

Summary

Cofense details campaigns targeting hotel staff with fake guest complaints that deliver EtherRAT or TONResolver. The malware retrieves changeable C2 addresses from public blockchains, complicating conventional infrastructure takedowns.

Key points

  • Emails posing as guest complaints, reviews, or inquiries prompt hotel staff to open an archive containing an LNK shortcut disguised with a JPG extension.
  • Running the shortcut downloads a Node.js runtime and installs either EtherRAT or TONResolver.
  • EtherRAT retrieves C2 data from Ethereum smart-contract storage; TONResolver reads data associated with a TON wallet or smart contract.
  • Threat actors can update blockchain-stored C2 addresses through transactions, making conventional domain or hosting takedowns alone ineffective.
  • Cofense assesses with moderate confidence that the campaigns continue earlier Booking.com-spoofing activity, but says shared tools could also be used by separate actors.
  • Cofense recommends scrutinizing unsolicited, urgent complaint emails and training staff to recognize malicious messages.

Article Details

Attack Vectors
  • Fake guest complaints, negative reviews, and accommodation inquiries sent to hotel front desk, reservations, or guest relations staff link to archives containing malicious LNK shortcuts disguised as JPG images.
  • Some malicious messages are sent as replies within email threads after an initially legitimate conversation.
  • Executing the disguised LNK downloads a NodeJS runtime environment and installs EtherRAT or TONResolver.
  • Archives also contain a dummy MP4 whose size changes between downloads, likely to produce different hashes and reduce static hash-based detection effectiveness.
  • Earlier Booking.com-spoofing emails linked to fake CAPTCHA pages that placed malicious scripts on the clipboard and instructed recipients to execute them through the Windows Run dialog.
  • EtherRAT and TONResolver retrieve changing C2 addresses from public blockchain data rather than relying on hardcoded domains or IP addresses.
Defensive Notes
  • Train employees to recognize malicious email indicators and apply consistent scrutiny to unsolicited complaints or negative reviews, particularly those threatening immediate consequences.
  • Do not rely solely on static email wording or file hashes: lure wording varies substantially, and the dummy MP4 changes size between downloads.
  • Conventional domain and IP takedowns alone cannot prevent infected hosts from retrieving replacement C2 addresses from persistent blockchain records.
  • Requests to public blockchain APIs are not inherently malicious and can blend with legitimate cryptocurrency traffic.
  • Blocking Ethereum API access alone may not cover malware that resolves C2 infrastructure through TON APIs.

Indicators of compromise

TypeIndicatorContext
DOMAINamanohuguta[.]cfdTONResolver C2 domain associated with the TON smart contract examined in ATR 422158.
DOMAINfdffofofofo4[.]comEtherRAT C2 domain associated with the Ethereum smart contract examined in ATR 422147.
DOMAINhsaertyuoang34[.]sbsTONResolver C2 domain associated with the TON smart contract examined in ATR 422158.
DOMAINnjzlopghznkamkl[.]cfdTONResolver C2 domain associated with the TON smart contract examined in ATR 422158.
DOMAINnuypoiaklber[.]lolTONResolver C2 domain associated with the TON smart contract examined in ATR 422158.
DOMAINtonajukbhuakpo2[.]shopTONResolver C2 domain associated with the TON smart contract examined in ATR 422158.
DOMAINzloapobikahy23[.]bondTONResolver C2 domain associated with the TON smart contract examined in ATR 422158.

MITRE ATT&CK

People

Malware

Products

Industries

Related Articles