Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access

montagelips.info

TLP:CLEAR
Active

Domain

Description

Since April 2026, a sophisticated multi-stage intrusion campaign has targeted hospitality and hotel organizations across Europe and Asia. The operation uses photo-themed ZIP archives containing malicious shortcut files disguised as images. When executed, these shortcuts initiate an attack chain involving obfuscated PowerShell, Node.js-based implants, and dual registry persistence mechanisms. The threat actor exploits legitimate services like Calendly and Google redirects for phishing delivery, employing authentication laundering to bypass email security controls. The campaign evolved through two waves, introducing .NET DLL compilation, Cloudflare-fronted infrastructure, and refined obfuscation techniques. Post-compromise activities include command-and-control beaconing over non-standard ports, forced shutdowns, and portable executable compilation, suggesting preparation for additional malicious operations.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
Pattern Type
STIX
Confidence
75%
Valid From
Jul 26, 2026 04:00
Total Sightings
0
Added
Jul 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of montagelips.info

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.