Fake Guest Photos Are Handing Hackers Long-Term Access to Hotel Networks

Two separate campaigns are targeting hotel front desks and booking teams with booby-trapped zip files dressed up as guest photographs, and the goal isn't a quick smash-and-grab. It's a quiet, lasting foothold.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration for the story: Fake Guest Photos Are Handing Hackers Long-Term Access to Hotel Networks
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Microsoft tracked a phishing campaign hitting hotels across Europe and Asia that began at least as early as April 2025.
  • A separate Trend Micro investigation found similar attacks targeting Japanese hotels partnered with Booking.com, discovered in late May 2026.
  • Both campaigns trick staff into opening zip files containing fake image shortcuts that silently install remote-access software.
  • The Trend Micro campaign uses a technique called blockchain command-and-control, which hides the hackers' server address inside a public cryptocurrency network, making it nearly impossible to shut down by conventional means.
  • Neither campaign appears aimed at immediate ransom or theft. The goal is quiet, lasting access for later exploitation.

Hotel staff field dozens of guest requests every shift: complaints about rooms, photos of suspected bedbugs, reservation disputes. Criminals have noticed.

Two research teams, one at Microsoft and one at Trend Micro, have documented phishing campaigns aimed squarely at the hospitality industry. We first reported the Microsoft side of this story on 26 June in "Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant"; the Trend Micro campaign, targeting Japanese Booking.com partners, is the newer wrinkle. The emails mimic the mundane guest correspondence that front-desk and reservations workers handle every day.

How did the hackers get in?

Victims received emails pretending to be from guests: complaints, health inspection notices, stay reviews, with a zip file attached, supposedly containing photographs. Inside was a Windows shortcut file, a type normally used to link to an application, disguised as an image. Opening it triggered a hidden chain of software instructions that installed a persistent implant, a small concealed program that keeps a channel open for the hackers to return through.

Microsoft found that the criminals routed their emails through legitimate services, including the scheduling tool Calendly and Google's link-shortening system, so that standard email security checks would see a trustworthy sender. Microsoft's researchers called this "authentication laundering." Think of it as mailing a threatening letter inside an envelope stamped by a trusted courier: the courier's mark gets past the gate, not the letter's contents.

How does blockchain make this harder to stop?

The Trend Micro campaign conceals its control infrastructure more aggressively. The malware it delivers, called TONResolver, a JavaScript-based remote-access trojan, receives its instructions by looking up an address stored inside a smart contract on The Open Network (TON) blockchain, a public decentralised ledger most people associate with cryptocurrency. Because no single company owns the blockchain, law enforcement cannot simply seize a server or block a domain to cut off the hackers.

"If the C2 server gets taken down, the attacker just updates the domain inside the smart contract and every infected machine reconnects automatically," Denis Calderone, CTO at Suzu Labs, told Dark Reading. "There's no server to seize and no domain to sinkhole."

The same technique appeared in the recent Trivy supply-chain attack, which Calderone says signals a shift: blockchain command-and-control is moving from experimental to routine. Our earlier story on coordinated C2 takedowns shows exactly why that resilience matters to attackers.

Neither campaign rushed to demand ransom. Staying hidden, stealing login credentials, moving through the hotel's wider network, or dropping additional malicious software later, was the priority in both cases.

Should you worry?

If you work in hospitality, treat any emailed zip file claiming to contain guest photos as suspicious, even if the sender's address looks plausible. Tell your IT team immediately if you opened one. Guests whose data sits in hotel reservation systems should watch for unexpected account activity or password-reset emails they didn't request.

Both Microsoft and Trend Micro published detailed indicators of compromise. Calderone's advice was direct: "Restrict PowerShell and Node.js execution on front-desk and reservation systems at a minimum. If you see node.exe spawning on a reservations terminal, that's your indicator." Trend Micro adds that most businesses have no reason to reach blockchain platforms at all, so blocking that traffic entirely cuts the attack chain before TONResolver can phone home.

© 2026 Threat Vectr