
Chaos RAT Masquerades as Windows Update
Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate…
The recap describes a real spam campaign targeting hospitality workers with booking-related messages. Victims are lured to click a Google-hosted link that leads to a malicious ZIP file; opening it triggers a hidden PowerShell command that installs a Node.js-based backdoor.
This campaign targets hospitality workers with booking-themed spam emails designed to look like ordinary reservation requests. The message directs recipients to a link hosted on Google Share, a choice that lends the email a veneer of legitimacy while also helping it slip past email security filters. Clicking through leads to a malicious ZIP file. Inside the archive is not a normal document but a Windows shortcut (.LNK) file. Opening that shortcut silently executes a hidden PowerShell command, which in turn downloads a legitimate node.exe binary and uses it to deploy a Node.js based backdoor on the victim's machine.
The lure plays directly into the daily workflow of front desk, reservations, and hospitality operations staff, who routinely receive and act on booking and reservation messages from guests or third-party services. Because reviewing reservation details is a normal part of the job, an unexpected booking email does not immediately stand out as suspicious. Hosting the malicious link on a well-known file-sharing platform like Google Share adds a layer of perceived trust and helps the email bypass automated filtering that might otherwise flag less reputable domains.
Hospitality staff in front desk, reservations, and administrative roles should be trained to treat unsolicited booking or reservation emails with caution, particularly when they push urgency around downloading files. File-sharing links, even from recognizable platforms, should not be treated as inherently safe since attackers can abuse trusted hosting to bypass filters. Staff should be taught to recognize that legitimate reservation documents are rarely delivered as shortcut files inside a ZIP archive, and any such file should be reported to IT or security rather than opened. Reinforcing these habits through realistic, role-specific awareness training can help reduce the chance that a booking-themed lure leads to a successful compromise across hospitality and travel accommodation environments.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers send emails with booking-themed lures to hospitality workers, pointing to a link hosted on Google Share. Clicking it leads to a malicious ZIP file containing a Windows shortcut that runs a hidden PowerShell command, which downloads a legitimate node.exe and deploys a Node.js based backdoor.
The threat actor abuses Google Share hosting to make the link look legitimate and to help the message evade email security filtering.
Instead of a normal document like a PDF or DOCX, the ZIP contains a Windows shortcut (.LNK) file, which is used to trigger the hidden PowerShell command.
The campaign targets front desk, reservations, hotel management, and hospitality operations staff who regularly handle booking and reservation requests.
You get an email: “Booking request – please confirm reservation details.” Looks like easy business, right? Inside, there’s a Google Drive or Google Share link to download “booking details” as a ZIP file. You open it, and instead of a PDF, there’s a weird shortcut file ending in .LNK. Clicking that .LNK silently runs PowerShell, pulls down a legit-looking node.exe, and installs a Node.js backdoor, giving someone remote access while you think you’re just checking a reservation. Here’s the move: if a booking email makes you download a ZIP and the “document” is a .LNK shortcut, stop and report it to IT or Security, don’t open it.

Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…