s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.tonrat

📛 Threat Title

Malware family: TonRAT

Category: TonRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.tonrat`. Printable name: TonRAT. Aliases: TONResolver.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cybersixt.com

    M ICROSOFT warns of a phishing campaign targeting the hospitality sector using fake guest complaint emails that install a malware called TonRAT . Running since April 2026, the campaign employs an authentication laundering technique, exploiting platforms like Calendly and Google to bypass security protocols. The phishing emails, disguised as notifications about health or guest issues, are sent ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the TonRAT malware family including references, samples and yara signatures.

  • web:news.shield53.com

    Malware & Exploits Hotels Under Siege: TonRAT Phishing Campaign Exploits Hospitality Staff with Fake Guest Complaints A sophisticated phishing campaign targeting hotel front desks has been deploying TonRAT malware since April 2026, using legitimate services like Calendly and Google to bypass email authentication and establish resilient persistence.

  • web:qpulse.quasarcybertech.com

    This campaign poses a significant risk to hospitality operations because the TonRAT implant provides durable access to front-desk and reservation systems. Because the attackers use legitimate infrastructure like Calendly and Google for delivery, traditional email security filters relying solely on SPF/DKIM/DMARC may fail to block these messages ...

  • web:securityaffairs.com

    Microsoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence.

  • web:socprime.com

    A sophisticated multi-stage malware campaign is targeting the hotel sector through emails disguised as Booking.com notifications. The intrusion chain combines malicious LNK files, PowerShell scripts, and a Node.js-based remote access trojan known as TonRAT .

  • web:techjacksolutions.com

    Executive Summary An active phishing campaign, active since April 2026, is targeting hotel front-desk staff across Europe and Asia with a Node.js-based remote access trojan called TonRAT . Attackers abuse trusted platforms, Calendly booking links and Google redirect URLs, to pass email authentication checks, delivering malware that communicates via the TON blockchain, making standard domain ...

  • web:undercodetesting.com

    Learning Objectives Understand the complete multi-stage infection chain from phishing email to TonRAT execution Analyze how attackers abuse legitimate services (Calendly, SendGrid, Node.js official distribution) to evade detection Learn detection and mitigation strategies for Node.js-based malware with blockchain-powered C2 infrastructure

  • web:www.proarch.com

    New TonRAT phishing campaign uses Calendly notifications and Google redirects to install Node.js malware . Learn the attack chain, IOCs, and defenses.

  • web:www.trendmicro.com

    The malware , TONResolver, appears to function as an initial access and command-execution foothold, and observed follow-on activity indicates potential credential theft and further compromise. By storing the C&C server domain in a TON smart contract, attackers can swap in a new server at any time, even if the current one is blocked or taken down.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.