New Multi-Stage LNK Attack Targets Hospitality Firms With Node.js Backdoor
ID: e9fba04e-7ac5-5c4b-8a06-0b495fa6fb5e
STIX ID: report--e9fba04e-7ac5-5c4b-8a06-0b495fa6fb5e
Feed Name: GBHackers
LevelBlue describes an active, targeted phishing campaign against hospitality firms that uses Google Share links and malicious ZIPs containing .lnk shortcuts to execute obfuscated PowerShell, install a legitimate Node.js runtime, and launch a VM‑protected JavaScript backdoor. The multi-stage implant retrieves C2 information from the TON blockchain, communicates over encrypted WebSocket channels, persists via Run-key registry entries, and has yielded 400+ related samples, with indicators and behaviors defenders should monitor (suspicious .png.lnk files, unexpected Node downloads, TONAPI queries, outbound WebSockets).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
