What if a "photo" ZIP file was actually a hotel intrusion toolkit?
A multistage campaign targeted hotels in Japan and Europe using photo-themed ZIP archives, fake image shortcuts, obfuscated
#PowerShell, and a Node.js implant.
Thanks to
@msftsecurity for the 77 network IoCs, expanding which we uncovered 3,202 new artifacts → 2 client IPs, 5
#typosquatting domains, 1 likely malicious domain, 2,357 potential victim IPs, 2,840 email-connected domains, 123 malicious IPs, 144 IP-connected domains, and 95 string-connected domains.
Download the full Photo ZIP report →
main.whoisxmlapi.com/threat-…
#ThreatIntelligence #CyberSecurity#HospitalitySecurity#DNSIntel
#Infosec #CTI #ThreatResearch