Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says.

The company has not attributed the activity to a known threat actor, and the operators’ end goal is still unclear.

The lure plays to how hotels work.

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six

EU Commission: addictive design Instagram and Facebook in breach of the DSA

EU Commission: addictive design Instagram and Facebook in breach of the DSA Source: Hacker News

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint,