Back to Intel

Intel Node

Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access

lowapt2026-06-25T22:30:29+00:00source excerpt
apttradecraftdetectionwindowscloudemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives and fake image shortcut files to deliver a persistent Node.js implant and evade detection. The post Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access appeared first on Microsoft Security Blog .

In this article Attack chain overview Mitigation and protection guidance References Learn more Microsoft Threat Intelligence has identified an active multi-stage intrusion campaign targeting organizations in the hospitality and hotel industry since April 2026. We’ve observed this activity through aggregated threat intelligence and security signals across multiple organizations in Europe and Asia. Microsoft has not attributed this campaign to a known threat actor. The campaign uses photo-themed ZIP archives that the target users download through the browser.

These archives contain fake image shortcut files that, when launched, start an attack chain that relies on obfuscated PowerShell, a Node. js-based implant, dual registry persistence, and command-and-control (C2) communications over non-standard ports.

Read Original Source