Threat Summary
AlienVault OTX pulse data confirms an active, ongoing email-borne campaign targeting the accommodation and hospitality industry — hotels, resorts, and lodging operators — using socially engineered lures themed around fake guest complaints, negative reviews, and booking inquiries. This lure selection is deliberate: front-desk and customer-service staff are conditioned to open complaint-related attachments quickly, making the hospitality front office the soft underbelly of the enterprise perimeter.
The attack chain begins with a phishing email delivering a malicious LNK shortcut file disguised as an image (typically double-extension or icon-spoofed to appear as a JPG/PNG review screenshot). Execution of the shortcut kicks off a multi-stage loader sequence that ultimately deploys one of several RAT payloads — EtherRAT, TONResolver, PureRAT, or NetSupport Manager RAT (the latter abused in its legitimate-but-weaponized form).
What makes this campaign distinctive — and what elevates it from commodity phishing to an intelligence-worthy threat — is its abuse of public blockchain infrastructure for command-and-control resolution. EtherRAT queries Ethereum smart contract data and TONResolver queries the TON (The Open Network) blockchain via public APIs to resolve its C2 addresses. This gives the operators decentralized, takedown-resistant C2 infrastructure: there is no domain to seize and no server to sinkhole, because the C2 pointer lives on an immutable public ledger. The campaign's objective is persistent remote access to hospitality networks — a foothold valuable for payment card data theft, reservation system compromise, and downstream ransomware or data-extortion operations.
The presence of Cloudflare Tunnel (trycloudflare.com) hostnames in the indicator set confirms the operators are also using legitimate tunneling services to proxy staging and C2 traffic, further blending malicious traffic with trusted cloud infrastructure.
Threat Actor / Malware Profile
Attribution: Unknown — no named APT cluster has claimed this activity. The tooling mix (PureRAT + NetSupport Manager + blockchain C2 resolution) is consistent with a financially motivated initial-access operation, possibly sold or brokered onward.
EtherRAT
- Distribution: Malicious LNK files delivered via phishing emails themed as guest complaints/reviews.
- Payload behavior: Remote access trojan with shell command execution, file transfer, and surveillance capabilities.
- C2 communication: Resolves C2 by querying public Ethereum blockchain APIs — reading data from attacker-controlled smart contracts or transaction metadata to retrieve live C2 addresses. This defeats static blocklists and domain takedowns.
- Anti-analysis: Blockchain-based resolution means sandbox detonation without Ethereum API visibility reveals nothing; C2 addresses rotate on-chain.
TONResolver
- C2 communication: Functionally analogous to EtherRAT but resolves C2 infrastructure via the TON blockchain (Toncenter / public TON API endpoints), reading wallet or DNS-record data stored on-chain.
- Role: Frequently acts as a resolver/stager that fetches the follow-on payload (PureRAT or NetSupport Manager) once a live C2 is obtained.
PureRAT
- Payload behavior: Full-featured .NET RAT — keylogging, screen capture, credential harvesting, process injection, and plugin-based extensibility.
- Persistence: Registry Run keys and scheduled tasks under innocuous names; often installed per-user to avoid elevation prompts.
- Anti-analysis: Packing/obfuscation, AMSI bypass attempts, and environment checks before payload decryption.
NetSupport Manager RAT (abused legitimate tool)
- Payload behavior: Commercial remote-administration software weaponized as a RAT — signed binaries that evade many reputation-based controls.
- Persistence: Installs as a service or via startup folder; survives reboots by design.
- C2 communication: Standard NetSupport client32 protocol, often proxied through Cloudflare tunnels (
trycloudflare.com) to disguise egress.
Attack Chain Summary
- Phishing email (fake guest complaint/review/inquiry) → hospitality staff mailbox
- Malicious LNK disguised as image → spawns
powershell.exe/mshta.exe/cmd.exechild processes - Stage retrieval from attacker domains or Cloudflare tunnels
- EtherRAT / TONResolver queries Ethereum or TON blockchain APIs → resolves live C2
- PureRAT / NetSupport Manager deployed → persistence + full remote access
IOC Analysis
The pulse indicator set (15 total) is dominated by domains and hostnames, which is the expected shape for this campaign:
- Attacker-registered C2/staging domains:
gateway001kir.com,sslgateway001.com,waygatterol002.com,kadmecnp-643laolmd.com,lermontov-656idlop.com,perrine90-deltajohnsons.com. Note the naming patterns: pseudo-random concatenations and sequential numbering (gateway001,002) indicating scripted, bulk registration — a strong hunting heuristic. - Fast-flux / exotic TLD infrastructure:
zloapobikahy23.bond— the.bondTLD and DGA-like label are classic throwaway C2 markers. - Legitimate-service abuse:
lotus-vista-additions-joshua.trycloudflare.com— a Cloudflare Tunnel hostname. These are ephemeral, HTTPS-only, and blend into trusted Cloudflare egress. Blocking requires process-level or tunnel-specific detection, not IP blocking.
How SOC teams should operationalize:
- Push all domains/hostnames to DNS sinkhole and web proxy block lists immediately. Retrospectively query DNS logs for the past 90 days — blockchain C2 means these domains may have been resolved weeks ago under earlier campaign phases.
- For
trycloudflare.comindicators: do not block the parent domain (it will break legitimate tunnels). Instead, alert on any endpoint process spawningcloudflared.exeor establishing connections to*.trycloudflare.comoutside sanctioned IT use. - Alert on outbound HTTPS to public blockchain API endpoints (e.g.,
api.etherscan.io,eth-mainnet.g.alchemy.com,toncenter.com,api.ton.cat) originating from non-browser, non-developer processes — this is the highest-fidelity behavioral signal for EtherRAT/TONResolver. - Use AlertMonitor or your EDR's custom IOA engine to decode LNK execution telemetry — inspect command lines of LNK-spawned children for double-extension image lures (
.jpg.lnk,.png.lnk).
Detection Engineering
---
title: EtherRAT / TONResolver Blockchain API C2 Resolution
id: 7f3a91c2-4e5d-4a1b-9c8e-2d6f0a1b3c4d
status: experimental
description: Detects non-browser processes initiating network connections to public Ethereum or TON blockchain API endpoints, consistent with EtherRAT/TONResolver blockchain-based C2 resolution.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
- https://cofense.com/blog/from-guest-complaints-to-malware-blockchain-abuse-targets-hotels
logsource:
category: network_connection
product: windows
detection:
selection_api:
DestinationHostname|contains:
- 'api.etherscan.io'
- 'eth-mainnet.g.alchemy.com'
- 'mainnet.infura.io'
- 'toncenter.com'
- 'api.ton.cat'
- 'tonapi.io'
filter_browsers:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\firefox.exe'
- '\brave.exe'
condition: selection_api and not filter_browsers
falsepositives:
- Legitimate cryptocurrency wallet or development tooling
- Internal blockchain applications (allowlist by process hash)
level: high
tags:
- attack.command_and_control
- attack.t1071.001
- attack.t1102
---
title: Malicious LNK Disguised As Image Execution - Hospitality Phishing
id: 8b2c4d6e-1f3a-4b5c-8d9e-0a1b2c3d4e5f
status: experimental
description: Detects execution of LNK shortcut files with image double-extensions and suspicious child processes, matching the EtherRAT/TONResolver hospitality phishing lure pattern.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
- https://cofense.com/blog/from-guest-complaints-to-malware-blockchain-abuse-targets-hotels
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\explorer.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\mshta.exe'
- '\cmd.exe'
- '\wscript.exe'
- '\rundll32.exe'
selection_lure:
CommandLine|contains:
- '.jpg.lnk'
- '.jpeg.lnk'
- '.png.lnk'
- '.gif.lnk'
- '.pdf.lnk'
condition: selection_parent and selection_child and selection_lure
falsepositives:
- Rare legitimate user-created shortcuts (tune by file path and signer)
level: high
tags:
- attack.execution
- attack.t1204.002
- attack.t1059.001
---
title: EtherRAT Campaign Known C2 Domain Resolution
id: 9c3d5e7f-2a4b-4c6d-9e0f-1a2b3c4d5e6f
status: experimental
description: Detects DNS queries for known EtherRAT/TONResolver/PureRAT campaign C2 and staging domains from OTX pulse, including Cloudflare Tunnel abuse.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
- https://cofense.com/blog/from-guest-complaints-to-malware-blockchain-abuse-targets-hotels
logsource:
category: dns
product: windows
detection:
selection:
query|contains:
- 'gateway001kir.com'
- 'sslgateway001.com'
- 'waygatterol002.com'
- 'zloapobikahy23.bond'
- 'perrine90-deltajohnsons.com'
- 'kadmecnp-643laolmd.com'
- 'lermontov-656idlop.com'
- 'lotus-vista-additions-joshua.trycloudflare.com'
condition: selection
falsepositives:
- None expected; these are confirmed malicious infrastructure
level: critical
tags:
- attack.command_and_control
- attack.t1071
// EtherRAT / TONResolver hospitality campaign hunt - Microsoft Sentinel
// Hunts blockchain API C2 resolution, campaign domains, and LNK lure execution
let CampaignDomains = dynamic([
"gateway001001kir.com".Replace("001001","001"),
"sslgateway001.com",
"waygatterol002.com",
"zloapobikahy23.bond",
"perrine90-deltajohnsons.com",
"kadmecnp-643laolmd.com",
"lermontov-656idlop.com",
"lotus-vista-additions-joshua.trycloudflare.com"
]);
let BlockchainAPIs = dynamic([
"api.etherscan.io", "eth-mainnet.g.alchemy.com",
"mainnet.infura.io", "toncenter.com", "tonapi.io", "api.ton.cat"
]);
let Lookback = 14d;
let NetHits = DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemoteUrl has_any (CampaignDomains)
or (RemoteUrl has_any (BlockchainAPIs)
and InitiatingProcessFileName !in~ ("chrome.exe","msedge.exe","firefox.exe","brave.exe"))
| project TimeGenerated, DeviceName, RemoteUrl, InitiatingProcessFileName,
InitiatingProcessCommandLine, RemoteIP, ActionType, HuntSignal="NetworkC2";
let LnkHits = DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ ("powershell.exe","pwsh.exe","mshta.exe","cmd.exe","wscript.exe","rundll32.exe")
| where ProcessCommandLine has_any (".jpg.lnk",".jpeg.lnk",".png.lnk",".gif.lnk",".pdf.lnk")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine,
InitiatingProcessCommandLine, HuntSignal="LnkLureExec";
let TunnelHits = DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemoteUrl endswith ".trycloudflare.com"
| where InitiatingProcessFileName !in~ ("cloudflared.exe")
| project TimeGenerated, DeviceName, RemoteUrl, InitiatingProcessFileName,
InitiatingProcessCommandLine, RemoteIP, ActionType="", HuntSignal="CloudflareTunnelAbuse";
union NetHits, LnkHits, TunnelHits
| sort by TimeGenerated desc
# EtherRAT / TONResolver / PureRAT IOC & Artifact Hunt - Security Arsenal
# Run elevated on suspected hospitality endpoints or deploy fleet-wide via EDR/Intune
$ErrorActionPreference = 'SilentlyContinue'
$Report = @()
# 1. DNS cache check for campaign domains
$CampaignDomains = @('gateway001kir.com','sslgateway001.com','waygatterol002.com',
'zloapobikahy23.bond','perrine90-deltajohnsons.com','kadmecnp-643laolmd.com',
'lermontov-656idlop.com','lotus-vista-additions-joshua.trycloudflare.com')
$DnsCache = Get-DnsClientCache
foreach ($d in $CampaignDomains) {
$hit = $DnsCache | Where-Object { $_.Entry -like "*$d*" }
if ($hit) { $Report += [pscustomobject]@{Type='DNS_CACHE_HIT'; Indicator=$d; Detail=$hit.Data} }
}
# 2. Registry persistence - Run keys referencing blockchain terms or odd paths
$RunKeys = @('HKCU:\Software\Microsoft\Windows\CurrentVersion\Run',
'HKLM:\Software\Microsoft\Windows\CurrentVersion\Run')
foreach ($key in $RunKeys) {
Get-ItemProperty $key | ForEach-Object {
$_.PSObject.Properties | Where-Object {
$_.Value -match 'ether|tonresolver|purerat|client32|appdata.*\.lnk|blockchain'
} | ForEach-Object {
$Report += [pscustomobject]@{Type='REGISTRY_RUNKEY'; Indicator=$_.Name; Detail=$_.Value}
}
}
}
# 3. NetSupport Manager RAT artifacts (client32) outside sanctioned installs
$NSPaths = @("$env:ProgramFiles\NetSupport","${env:ProgramFiles(x86)}\NetSupport",
"$env:APPDATA\NetSupport","$env:LOCALAPPDATA\client32.exe")
foreach ($p in $NSPaths) {
if (Test-Path $p) { $Report += [pscustomobject]@{Type='NETSUPPORT_ARTIFACT'; Indicator=$p; Detail='Found on disk - verify legitimacy'} }
}
Get-Process client32 -ErrorAction SilentlyContinue | ForEach-Object {
$Report += [pscustomobject]@{Type='NETSUPPORT_PROCESS'; Indicator='client32.exe'; Detail=$_.Path}
}
# 4. Suspicious LNK files with image double-extensions (last 30 days)
$LurePaths = @($env:USERPROFILE + '\Downloads', $env:USERPROFILE + '\Desktop', $env:TEMP)
foreach ($lp in $LurePaths) {
Get-ChildItem $lp -Recurse -Include *.jpg.lnk,*.png.lnk,*.jpeg.lnk,*.pdf.lnk -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-30) } | ForEach-Object {
$Report += [pscustomobject]@{Type='LNK_LURE'; Indicator=$_.Name; Detail=$_.FullName}
}
}
# 5. Active connections to blockchain API endpoints
$BlockchainHosts = @('api.etherscan.io','toncenter.com','tonapi.io','mainnet.infura.io')
Get-NetTCPConnection -State Established | ForEach-Object {
try {
$resolved = (Resolve-DnsName $_.RemoteAddress -ErrorAction Stop).NameHost
if ($BlockchainHosts | Where-Object { $resolved -like "*$_*" }) {
$proc = Get-Process -Id $_.OwningProcess
$Report += [pscustomobject]@{Type='BLOCKCHAIN_C2_CONN'; Indicator=$resolved; Detail="$($proc.Name) -> $($_.RemoteAddress):$($_.RemotePort)"}
}
} catch {}
}
# 6. Scheduled tasks with suspicious names/actions
Get-ScheduledTask | Where-Object {
$_.TaskName -match 'ether|resolver|update.*svc|guest' -or
($_.Actions.Execute -match 'powershell|mshta|rundll32' -and $_.TaskPath -notlike '\Microsoft*')
} | ForEach-Object {
$Report += [pscustomobject]@{Type='SCHED_TASK'; Indicator=$_.TaskName; Detail=$_.Actions.Execute}
}
if ($Report.Count -gt 0) {
$Report | Format-Table -AutoSize
$Report | Export-Csv "$env:TEMP\EtherRAT_Hunt_$(hostname)_$(Get-Date -Format yyyyMMdd).csv" -NoTypeInformation
Write-Host "[!] $($Report.Count) findings - escalate to IR immediately" -ForegroundColor Red
} else {
Write-Host "[+] No EtherRAT/TONResolver indicators found on $(hostname)" -ForegroundColor Green
}
Response Priorities
Immediate (0–4 hours)
- Block all listed campaign domains at DNS sinkhole, secure web gateway, and EDR network protection. Add
zloapobikahy23.bondand thegateway00*/waygatterol*patterns to wildcard watchlists for the operator's bulk-registration naming scheme. - Deploy the three Sigma rules and the Sentinel KQL query; run the KQL retrospectively over 14–30 days of telemetry.
- Quarantine all inbound email containing
.lnkattachments outright — there is no legitimate business case for LNK-by-email in hospitality workflows. Detonate queued guest-complaint/review-themed emails in sandbox. - Hunt endpoints for
client32.exe(NetSupport) and LNK-lure artifacts using the PowerShell script on front-desk, reservations, and finance workstations first.
24 Hours
- Treat any confirmed EtherRAT/PureRAT execution as a full credential compromise. PureRAT's keylogging and credential-harvesting capability means every account touched on an infected host — especially hospitality PMS (property management system), OTA extranet (Booking.com/Expedia partner portals), and email credentials — must be reset from a clean device.
- Force revocation of active sessions/tokens for affected users; verify no mailbox forwarding rules or OAuth grants were added (common follow-on for reservation-fraud and invoice-diversion schemes).
- Review payment systems: hospitality endpoints with card-not-present transaction access should be audited for anomalous lookups during the exposure window.
- Alert on and investigate any
*.trycloudflare.comegress from endpoints; identify whether sanctionedcloudflaredusage exists in your environment and allowlist explicitly.
1 Week
- Architecture hardening: Block or alert on outbound connections from non-browser processes to public blockchain API endpoints (Ethereum/TON RPC and explorer APIs) at the egress proxy — this neutralizes the C2-resolution mechanism at the network layer for the entire malware family class.
- Enable LNK file execution logging and deploy attack surface reduction rules blocking child processes from Office/shortcut double-extension execution.
- Implement DMARC enforcement and detonation rewriting for complaint/review-themed inbound mail targeting front-desk distribution lists; run a targeted phishing-simulation for hospitality customer-service staff using this exact lure theme.
- Evaluate managed detection coverage for blockchain-C2 behaviors — this campaign demonstrates that domain takedown is no longer a viable disruption strategy against this class of adversary.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.