logo

New Multi-Stage LNK Attack Targets Hospitality Firms With Node.js Backdoor

ID: e9fba04e-7ac5-5c4b-8a06-0b495fa6fb5e

STIX ID: report--e9fba04e-7ac5-5c4b-8a06-0b495fa6fb5e

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-10

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

LevelBlue describes an active, targeted phishing campaign against hospitality firms that uses Google Share links and malicious ZIPs containing .lnk shortcuts to execute obfuscated PowerShell, install a legitimate Node.js runtime, and launch a VM‑protected JavaScript backdoor. The multi-stage implant retrieves C2 information from the TON blockchain, communicates over encrypted WebSocket channels, persists via Run-key registry entries, and has yielded 400+ related samples, with indicators and behaviors defenders should monitor (suspicious .png.lnk files, unexpected Node downloads, TONAPI queries, outbound WebSockets).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.