Hackers Utilize Negative Hotel Reviews to Spread AI-Variant Malware; Hiding C2 on Blockchain

Executive Summary

Cofense Intelligence is tracking email campaigns targeting the hospitality accommodation industry with fake guest complaints, negative reviews, and inquiry-related messages that deliver blockchain technology-abusing malware, via a report published 7 October 2026.

The campaigns use links to archive files containing malicious LNK shortcut files masquerading as JPG images, which ultimately install either EtherRAT or TONResolver. Both malware families resolve their command-and-control (C2) infrastructure by querying data stored on public blockchains rather than relying on hardcoded domains or IP addresses, allowing operators to rotate infrastructure through simple blockchain transactions, making identification difficult.

Cofense assesses with moderate confidence that the activity is a continuation of earlier major hospitality branded-spoofing campaigns based on overlapping lure themes and targeted industry sectors. Researchers also assess with moderate confidence that generative AI is being used to create unique email variations, making detection more difficult.

Key Takeaways

  • Earlier hospitality-branded spoofing campaigns utilized ClickFix fake CAPTCHA pages to deliver RATs such as PureRAT and NetSupport Manager. The latest campaigns have shifted to fabricated guest complaints, negative reviews, and legal threats that pressure hotel staff to review supposed evidence.
  • Email links lead to archive files containing a malicious LNK shortcut with a mismatched JPG extension and a dummy MP4 file. The MP4 file varies in size with each download, likely generating unique file hashes to reduce the effectiveness of static hash-based detections.
  • Running the LNK file downloads a legitimate NodeJS runtime environment and installs either EtherRAT or TONResolver. Both malware families rely on NodeJS and share the core design principle of resolving their current C2 address at runtime through public blockchain APIs.
  • EtherRAT retrieves C2 information from an Ethereum smart contract using public JSON-RPC requests such as eth_call, while TONResolver retrieves C2 information from data stored on the TON blockchain. Both use a “blockchain dead drop resolver” technique that allows threat actors to update C2 infrastructure without redistributing malware.
  • Storing C2 domains and IP addresses on public blockchains allows operators to rotate infrastructure through small transactions while making traditional domain and IP takedown efforts largely ineffective. Cofense recommends emphasizing user awareness training, scrutinizing complaint-related emails, investigating unexpected NodeJS activity, and correlating endpoint findings with email telemetry.

Indicators of Compromise

Cofense has provided the following Indicators of Compromise associated with the campaign, which is provided below for RH-ISAC Core Member awareness.

Malware

Indicator type

Source value

EtherRAT

Ethereum contract

0x277852e1C349b03c79E348018a8391bD21C412E8

EtherRAT

C2 URL

hxxps[://]gateway001kir[.]com

EtherRAT

C2 URL

hxxps[://]sslgateway001[.]com

EtherRAT

C2 URL

hxxps[://]waygatterol002[.]com

EtherRAT

C2 URL

hxxps[://]lotus-vista-additions-joshua[.]trycloudflare[.]com

EtherRAT

C2 URL

hxxps[://]perrine90-deltajohnsons[.]com

EtherRAT

C2 URL

hxxps[://]kadmecnp-643laolmd[.]com

EtherRAT

C2 URL

hxxps[://]lermontov-656idlop[.]com

EtherRAT

C2 URL

hxxps[://]dns1[.]southafricanorth[.]cloudapp[.]azure[.]com

EtherRAT

C2 domain

fdffofofofo4[.]com

EtherRAT

C2 URL

hxxps[://]update[.]norwayeast[.]cloudapp[.]azure[.]com

EtherRAT

C2 URL

hxxps[://]allres[.]southafricanorth[.]cloudapp[.]azure[.]com

EtherRAT

C2 URL

hxxps[://]synctimes[.]australiaeast[.]cloudapp[.]azure[.]com

EtherRAT

C2 URL

hxxps[://]opencode-setup-al[.]com

EtherRAT

C2 URL

hxxps[://]luxmaxing[.]southafricanorth[.]cloudapp[.]azure[.]com

TONResolver

TON contract

0:c66119f0e5635c4380441d7a79baf0c02a0ab7ea6cd78de06507fc5dc2c1a5d9

TONResolver

C2 domain

amanohuguta[.]cfd

TONResolver

C2 domain

hsaertyuoang34[.]sbs

TONResolver

C2 domain

zloapobikahy23[.]bond

TONResolver

C2 domain

tonajukbhuakpo2[.]shop

TONResolver

C2 domain

njzlopghznkamkl[.]cfd

TONResolver

C2 domain

nuypoiaklber[.]lol

More Recent Blog Posts

Somewhere in your organization this week, someone saved themselves a few hours by pasting company data into an AI tool nobody reviewed. They...

Executive Summary A joint law enforcement advisory conducted by the National Police Agency of Japan (NPA), National Cybersecurity Office of Japan (NCO), US...

Executive Summary An Infoblox cybersecurity report, published on 15 September 2026, has revealed that online casinos are being used to disguise and deploy...