TF-MAL-js.tonrat
📛 Threat Title
Malware family: TonRAT
Description
ThreatFox malware family `js.tonrat`. Printable name: TonRAT. Aliases: TONResolver.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersixt.com
M ICROSOFT warns of a phishing campaign targeting the hospitality sector using fake guest complaint emails that install a malware called TonRAT . Running since April 2026, the campaign employs an authentication laundering technique, exploiting platforms like Calendly and Google to bypass security protocols. The phishing emails, disguised as notifications about health or guest issues, are sent ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the TonRAT malware family including references, samples and yara signatures.
-
web:news.shield53.com
Malware & Exploits Hotels Under Siege: TonRAT Phishing Campaign Exploits Hospitality Staff with Fake Guest Complaints A sophisticated phishing campaign targeting hotel front desks has been deploying TonRAT malware since April 2026, using legitimate services like Calendly and Google to bypass email authentication and establish resilient persistence.
-
web:qpulse.quasarcybertech.com
This campaign poses a significant risk to hospitality operations because the TonRAT implant provides durable access to front-desk and reservation systems. Because the attackers use legitimate infrastructure like Calendly and Google for delivery, traditional email security filters relying solely on SPF/DKIM/DMARC may fail to block these messages ...
-
web:securityaffairs.com
Microsoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence.
-
web:socprime.com
A sophisticated multi-stage malware campaign is targeting the hotel sector through emails disguised as Booking.com notifications. The intrusion chain combines malicious LNK files, PowerShell scripts, and a Node.js-based remote access trojan known as TonRAT .
-
web:techjacksolutions.com
Executive Summary An active phishing campaign, active since April 2026, is targeting hotel front-desk staff across Europe and Asia with a Node.js-based remote access trojan called TonRAT . Attackers abuse trusted platforms, Calendly booking links and Google redirect URLs, to pass email authentication checks, delivering malware that communicates via the TON blockchain, making standard domain ...
-
web:undercodetesting.com
Learning Objectives Understand the complete multi-stage infection chain from phishing email to TonRAT execution Analyze how attackers abuse legitimate services (Calendly, SendGrid, Node.js official distribution) to evade detection Learn detection and mitigation strategies for Node.js-based malware with blockchain-powered C2 infrastructure
-
web:www.proarch.com
New TonRAT phishing campaign uses Calendly notifications and Google redirects to install Node.js malware . Learn the attack chain, IOCs, and defenses.
-
web:www.trendmicro.com
The malware , TONResolver, appears to function as an initial access and command-execution foothold, and observed follow-on activity indicates potential credential theft and further compromise. By storing the C&C server domain in a TON smart contract, attackers can swap in a new server at any time, even if the current one is blocked or taken down.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.