Microsoft has uncovered a sophisticated hotel phishing campaign targeting hospitality businesses across Europe and Asia.
The attackers disguise malware as photo attachments and trick hotel employees into opening them. Once activated, the files install malware that gives cybercriminals long-term access to infected systems. Microsoft has not linked the activity to a known threat group, and the attackers’ ultimate objective remains unclear.
Fake Photos Hide Malware
The hotel phishing campaign begins with an email that appears to come from a potential guest.
Messages often mention booking inquiries, customer complaints, bed bug reports, or accommodation reviews. The emails include a ZIP archive that supposedly contains photos.
Instead of images, the archive hides Windows shortcut files that look like PNG images. Because Windows hides known file extensions by default, employees may believe they are opening a harmless picture.
Malware Installs in the Background
Opening the fake image silently launches a chain of malicious commands.
The attack downloads a legitimate version of Node.js before using it to run a malicious JavaScript implant. The malware creates persistence, allowing attackers to reconnect even after the victim restarts the computer.
Microsoft says the malware can steal credentials, gather system information, explore corporate networks, and deploy additional payloads later.
Trusted Services Help Deliver the Attack
One of the most unusual aspects of the hotel phishing campaign is how attackers deliver the emails.
Microsoft says the operators abuse Calendly’s notification system together with Google’s URL redirection service. The company refers to this technique as authentication laundering.
Because the messages originate from legitimate infrastructure, they successfully pass SPF, DKIM, and DMARC email authentication checks. That makes the phishing emails much harder for traditional email security tools to detect.
Hotels Remain Attractive Targets
Hotels continue to attract cybercriminals because employees regularly receive messages from guests, booking platforms, and travel partners.
Attackers exploit that daily workflow by creating emails that appear routine and urgent. Front desk, reservation, and customer support staff often face pressure to respond quickly, increasing the likelihood that someone will open a malicious attachment.
Microsoft Recommends Behavior-Based Detection
Microsoft advises organizations not to rely solely on email authentication when defending against hotel phishing attacks.
Instead, security teams should monitor for suspicious PowerShell activity, unexpected Node.js execution, new registry persistence entries, and connections to recently registered domains. Regular employee awareness training can also reduce the chances of staff opening malicious attachments.
Although Microsoft has not reported ransomware or confirmed data theft, the company warns that the attackers already have a reliable way to establish persistent access. That makes early detection critical for hospitality organizations.


0 responses to “Microsoft Warns of Hotel Phishing Campaign Targeting Europe and Asia”