A sophisticated phishing campaign observed in May 2026 targets Japanese accommodation facilities partnering with Booking.com. Attackers impersonate guest complaints and review requests through emails, tricking hotel staff into downloading malicious ZIP files containing shortcut links disguised as photos. The malware, TONResolver, employs The Open Network blockchain platform as a dead drop resolver to dynamically retrieve command-and-control server addresses, making detection and takedown difficult. The attack uses Node.js with VM-based obfuscation and establishes encrypted WebSocket connections using ECDH key exchange and AES-256-CBC encryption. Two delivery methods were identified: bulk phishing and conversational attacks via Gmail that build trust before delivering malicious URLs. Once infected, endpoints maintain persistent Keepalive connections awaiting attacker commands for credential theft and additional malware deployment, with observed follow-on activity targeting browser-stored credentials from Ch...
Created: 2026-06-30
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。