Fake Guest Complaints Deliver Hotel RAT Malware

Cofense · High sophistication
Last updated October 8, 2026

Cofense tracked real email campaigns targeting hotels with fake guest complaints, reviews, and inquiries. The emails push staff to click a link and open what looks like a photo or video, but it leads to a disguised Windows shortcut (LNK) that installs remote-access malware. The malware hides its control servers by pulling them from public blockchains, making takedowns and blocking harder.

How the attack worked

This campaign tracked by Cofense targets hotel staff with emails posing as guest complaints, negative reviews, or booking inquiries. The message asks the recipient to review a photo or document as evidence. The embedded link leads to an archive file that, instead of containing an actual image, holds a Windows shortcut (LNK) disguised with a mismatched .JPG extension. Opening this file installs remote-access malware, identified as EtherRAT or TONResolver, giving attackers a foothold on hotel systems.

A related and earlier set of campaigns spoofed Booking.com, directing victims to a fake CAPTCHA page. Rather than delivering malware through a download, this version used a ClickFix technique: the page instructed the victim to copy a "verification code" and paste it into the Windows Run dialog (Win+R), which actually executed a malicious script.

Why it succeeded

The pretexts used in both scenarios map closely to the daily workflow of front desk, reservations, and guest relations staff, who routinely respond to guest complaints and booking messages. This familiarity lowers suspicion. Cofense also notes the attacker may be using generative AI to create unique email text for each message, which can make pattern-based detection harder.

The malware's infrastructure adds another layer of resilience. By storing command-and-control addresses on public blockchains such as Ethereum or TON, attackers can rotate infrastructure cheaply and quickly. Because blockchain data cannot be removed, this makes conventional domain and IP takedown requests largely ineffective against this threat.

What to watch for

  • An unexpected guest complaint, review, or inquiry email pushing urgency to open a photo or document
  • A downloaded "photo" or "video" that is actually a compressed archive containing a shortcut (LNK) file
  • A file extension mismatch, such as an LNK file appearing to be a .JPG
  • A CAPTCHA page that asks you to paste a "verification code" into the Windows Run dialog (Win+R)
  • Links that lead to a lookalike Booking.com page rather than a known, trusted portal

How to build resistance

  • Treat any guest complaint or review email that pushes you to open an attached or linked file as high risk, and verify through a separate trusted channel before opening anything
  • Train staff to never open "photos" or "videos" that arrive as compressed downloads containing shortcut files, and to escalate these to IT or security instead
  • Reinforce that no legitimate verification process ever requires pasting text into the Windows Run dialog
  • Because attackers can rotate infrastructure quickly using blockchain-based command-and-control, prioritize user behavior training and layered detection over reliance on blocking specific domains or IP addresses

Key findings

  • Hotels are targeted with emails posing as guest complaints, reviews, or inquiries that push staff to review an attached/linked “photo” or “document.”
  • Links lead to an archive containing a malicious Windows shortcut (LNK) disguised as a JPG image; running it installs EtherRAT or TONResolver.
  • The malware families pull their command-and-control (C2) addresses from public blockchains (Ethereum or TON), enabling cheap and rapid C2 rotation and making takedowns difficult.
  • Earlier related campaigns spoofed Booking.com and used ClickFix fake CAPTCHA pages to trick victims into pasting a malicious script into Windows Run (Win+R).
  • Cofense believes the attacker may be using generative AI to create unique email text, making detection harder.

Who’s being targeted

  • Commonly targeted roles: Front Desk, Reservations, Guest Relations, Hotel Management, IT Helpdesk, Security Operations (SOC).
  • Affected industries: Hotels and travel accommodation, Hospitality, Travel services (online travel agency workflows).
  • Attack channels: email, website.
  • Impersonated: Hotel guest (direct email to the property), Booking.com (spoofed).

Red flags to watch for

  • A ‘photo’ that arrives as a downloaded archive with a shortcut (LNK) instead of a real image
  • File extension mismatch (LNK masquerading as .JPG)
  • Unexpected complaint/review email pushing urgency to open files
  • A CAPTCHA page instructing users to paste text into Windows Run (Win+R)
  • ‘Verification code’ is automatically placed on the clipboard and asks for unusual actions
  • Link leads to a lookalike Booking.com site rather than a trusted workflow/portal
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake guest complaint attack work?

Attackers email hotel staff posing as guests with complaints or reviews, asking them to review a photo or document. The link leads to an archive containing a Windows shortcut (LNK) disguised as a JPG, which installs remote-access malware such as EtherRAT or TONResolver when opened.

Why is this malware hard to block or take down?

The malware pulls its command-and-control addresses from public blockchains like Ethereum or TON, letting attackers rotate infrastructure cheaply and making conventional domain or IP takedowns largely ineffective.

What other tactic have attackers used against hotels?

Earlier related campaigns spoofed Booking.com and used fake CAPTCHA pages (ClickFix) that instructed victims to paste a malicious script into the Windows Run dialog via Win+R.

Who at a hotel is most likely to be targeted?

Front desk, reservations, and guest relations staff are the primary targets since they routinely handle guest complaints, reviews, and booking inquiries.

Read the video transcript

You get an email: “Guest complaint – please review the attached photo evidence.” Looks routine, right? You click the link, download a zip, and inside is what looks like a JPG. But it’s actually a Windows shortcut, an LNK, that quietly installs EtherRAT or TONResolver remote access malware. Earlier runs even spoofed Booking.com and a fake CAPTCHA page that tells you to press Win+R and paste a “verification code” that’s really malware. Once you run it, their control servers hide behind public blockchains, so they’re hard to shut down. Your move: if a guest complaint or Booking-style email makes you download a zip or paste anything into Win+R, stop and send it to IT or security, do not open or run it.

Categories

Similar attacks

Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
Voucher Lure Drops RAT via FTP Banner Tricks

Voucher Lure Drops RAT via FTP Banner Tricks

Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads,…

August 25, 2026
Mirage Kitten Uses Fake Hiring Lures to Drop Malware

Mirage Kitten Uses Fake Hiring Lures to Drop Malware

Researchers report Mirage Kitten (an espionage-focused threat group) targeted organizations in the Middle East and Africa using highly tailored spear‑phishing. The lures included recruitment-themed messages impersonating trusted brands/hiring sites and fake videoconferencing pages that redirected…

July 28, 2026
Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026