Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor
A multi-stage attack campaign uses malicious LNK files delivered via booking-themed phishing emails to deploy a Node.js-based backdoor. The LNK files use bigint arithmetic obfuscation to reconstruct C2 URLs, download a PowerShell payload that deploys a legitimate node.exe binary, and execute an AES-128-CBC encrypted JavaScript backdoor. The backdoor retrieves its C2 address from the TON blockchain using the EtherHiding technique, employs a custom bytecode VM interpreter for defense evasion, and supports downloading and executing additional payloads including PE files, PowerShell, and JavaScript.
- domainaboutbookphoto[.]proC2 domain observed in LNK samples
- domainamanohuguta[.]cfdC2 domain retrieved from TON blockchain transaction history (Feb 7, 2026)
- domainbigfrogs[.]infoC2 domain observed in LNK samples
- domainbook-imagegallery[.]infoC2 domain observed in LNK samples
- domainbook-photopage[.]infoC2 domain observed in LNK samples
- domainbubblekip[.]infoC2 domain observed in LNK samples
- domaincheckphoto-bookin[.]comC2 domain observed in LNK samples
- domainconfbookphoto[.]infoC2 domain observed in LNK samples
- domaindancamp[.]infoC2 domain observed in LNK samples
- domainderacefight[.]infoC2 domain observed in LNK samples
- domaindsjkaksfks324das[.]comC2 domain observed in LNK samples
- domainfancystraits[.]infoC2 domain observed in LNK samples
- domainfellshow[.]infoC2 domain observed in LNK samples
- domainflamecube[.]infoC2 domain observed in LNK samples
- domainhaddjskak827sja[.]comC2 domain observed in LNK samples
- domainhotelphotoadm[.]infoC2 domain observed in LNK samples
- domainhsaertyuoang34[.]sbsC2 domain retrieved from TON blockchain transaction history (Feb 10, 2026)
- domainhubsecure[.]infoC2 domain observed in LNK samples
- domainjsdakksd283ksl[.]comC2 domain observed in LNK samples
- domainkeysrace[.]infoC2 domain observed in LNK samples
- domainlastnight[.]infoFrequently observed C2 domain across multiple LNK samples in the campaign
- domainlightsnow[.]infoC2 domain observed in LNK samples
- domainmarmoteilefinance[.]comC2 domain observed in LNK samples
- domainphoto-132454[.]cfdC2 domain observed in LNK samples
- domainphoto-26653[.]cfdC2 domain observed in LNK samples
- domainphoto-26654[.]cfdC2 domain observed in LNK samples
- domainphoto-26656[.]cfdC2 domain observed in LNK samples
- domainphoto-27657[.]cfdC2 domain observed in LNK samples
- domainphoto-62454[.]cfdC2 domain observed in LNK samples
- domainphotobookadm[.]proMost frequently observed C2 domain across LNK samples, extracted from multiple SHA1 samples in the campaign
- domainphotohotels-visit[.]cloudC2 domain observed in LNK samples
- domainphoto-pagebook[.]infoC2 domain observed in LNK samples
- domainrecordstrace[.]infoC2 domain reconstructed from bigint obfuscation in LNK PowerShell command; also used as redirect URL for payload delivery
- domainreplyjoke[.]infoC2 domain observed in LNK samples
- domainsafegallery[.]infoC2 domain observed in LNK samples
- domainstrayweirds[.]infoC2 domain observed in LNK samples
- domaintonajukbhuakpo2[.]shopMost recent C2 domain retrieved from TON blockchain smart contract (updated June 2, 2026)
- domaintracerecord[.]infoC2 domain observed in LNK samples
- domainvault-docs-x[.]infoC2 domain observed in LNK samples
- domainzloapobikahy23[.]bondC2 domain retrieved from TON blockchain transaction history (Feb 20, 2026)
- filenameuTmuR2wVd.jsDropped Node.js backdoor payload file decrypted via AES-128-CBC and executed by node.exe
- mutex0:c66119f0e5635c4380441d7a79baf0c02a0ab7ea6cd78de06507fc5dc2c1a5d9TON blockchain smart contract account ID used for EtherHiding C2 retrieval; querying this account returns the current C2 domain
- mutexwin-5r0dsv23ed0Shared MachineID across 400+ LNK samples used for campaign tracking; earliest submission dating back to March 2026
- sha10451e7e75af3c2917a38753db2642619b8f4a0fdLNK sample with C2 bokconfphoto.info
- sha10993e576ea97208db8cd9ee651f6eb6382a6565aLNK sample with C2 photobookadm.pro
- sha10a0378a8e1b2bcf2a6d71ee8d39572897a48ab46LNK sample with C2 lastnight.info
- sha10b6e6d9c0091b1f8580bee455eb2199a4fe8a7e0LNK sample with C2 photobookadm.pro
- sha10cae9af236ae7ebbb072b058bb65ea6ed7592aaeLNK sample with C2 book-photopage.info
- sha10d9796ccb481b09bd92bbe1d7719d0939f645514LNK sample with C2 photo-132454.cfd
- sha10ddc606b48c4dd85cad09ffcb2fe560f68e63868LNK sample with C2 deracefight.info
- sha111838c2e3134991402e40a1744aa4c1f93447407LNK sample with C2 photobookadm.pro
- sha111b2f77a7abf1593648bbcc5bdeb27c4f890aef3LNK sample with C2 photo-26654.cfd
- sha117abeb78bb862d702d4e63d746c58d2d805d71eeLNK sample with C2 haddjskak827sja.com
- sha118949de1c7550d93e7d58ba545c2ab9703e47d51LNK sample with C2 jsdakksd283ksl.com
- sha118a720ebe0bc1ea1aeea9b495b419cc929c427aaLNK sample with C2 photo-pagebook.info
- sha1194fb8cbab8b030944e9a1ec44f2e4383f394589LNK sample with C2 replyjoke.info
- sha1206810a3effe5e477ffc441731b58f7f6cd2c04bLNK sample with C2 checkphoto-bookin.com
- sha127a7c5f0dcaf9ed18aa41340aa95d4d5778d7708LNK sample with C2 keysrace.info
- sha127e1eeb34bd8bd4b54760f15c88dd33f58507e09LNK sample with C2 lastnight.info
- sha12aab7ce372244d0ad882c45cc76579f570d5993bLNK sample with C2 bigfrogs.info
- sha12cab6043e2cf54bb1b46357798fba2d8d0d62e77LNK sample with C2 book-photopage.info
- sha12f9d50d3b166a667fe6b7a05da7039a8029c79b3LNK sample with C2 fellshow.info
- sha1307c3a41a56e67ff6d3026c3cd6e35b751f1eafbLNK sample with C2 lastnight.info
- sha133f6d432464c20bbdf019f62510435e9a45e29bcLNK sample with C2 photo-27657.cfd
- sha137b61fb43cf3aee0c0c6b3347abd018fc5eb0a5cLNK sample with C2 photobookadm.pro
- sha1391485c342138e8d137d88f927423eb5d7c00ad6LNK sample with C2 vault-docs-x.info
- sha1399712edc298a35e2cb643353b7fcfe4327e173bLNK sample with C2 bigfrogs.info
- sha13c908051cdef94e60b6f444e8719d291a57a2941LNK sample with C2 marmoteilefinance.com
- sha13d84d37393e244a76c24dfd9eebd0d20914166e6LNK sample with C2 photobookadm.pro
- sha142b40f25d025f23e42aa44f98466ce08bf022f26LNK sample with C2 photobookadm.pro
- sha1435b00e224f2e001018ed52aff2bd35706614297LNK sample with C2 keysrace.info
- sha14c98348b9bc57485d0624a5fc7838372566aacd7LNK sample with C2 photobookadm.pro
- sha14d901d5bd6c467f4bedfb0b968eb4c42902cf588LNK sample with C2 keysrace.info
- sha14e3baea41d73967aac96b3cb6525b9edb0ccacd8LNK sample with C2 strayweirds.info
- sha14edec9cff71c5467808c0a919ba05f13489d21abLNK sample with C2 dancamp.info
- sha154740686b96e9702cc376d6b04f89105d7700408LNK sample with C2 bigfrogs.info
- sha1582cd134c017435b027a2fea86f4e584d69a214fLNK sample with C2 photobookadm.pro
- sha15a14c0a131c4e5a729a28556b119876651a4047fLNK sample with C2 photobookadm.pro
- sha15a944255ee92ba70654d6ed73a52b5de22942340LNK sample with C2 hotelphotoadm.info
- sha15c21735b6a823a85730b03a71fe339082c417732LNK sample with C2 strayweirds.info
- sha15c80d4af9e9251f2303b88c51435dba09b24177aLNK sample with C2 hotelphotoadm.info
- sha15daab9743a4c80415d7261d2c2b3720140890e2bLNK sample with C2 photobookadm.pro
- sha15edc16ff32ff12ee2bf0abbc85a62b93eddab3b3LNK sample with C2 photobookadm.pro
- sha16145aabf54337e633670aa2e82835fae97612a5dLNK sample with C2 aboutbookphoto.pro
- sha1625cdb454461e7e82ba9b73028ddbdcbf0b5a7abLNK sample with C2 photobookadm.pro
- sha165b2a34be17b3d31221d55f9829f7d876634eaedLNK sample with C2 tracerecord.info
- sha169b570e6aa1d50e4bbd89c653eb1b97dab77f174LNK sample with C2 photobookadm.pro
- sha16a0bf6e890b24870597befcb447693a598fbd897LNK sample with C2 hotelphotoadm.info
- sha16f171cc3fe263ff8257c4a8cc38b1cf71fd46343LNK sample with C2 photobookadm.pro
- sha1717e816d99377e285f894457d7a662d85f39053fLNK sample with C2 fancystraits.info
- sha17ae18cb6532f2ebb0b6231509541118b52583dc0LNK sample with C2 photobookadm.pro
- sha17ba0659c3c33ff97a3c8e10a304b26a58f450b4eLNK sample with C2 flamecube.info
- sha17e05edb4a326c6b80ca937d602d43590bb73d68cLNK sample with C2 fancystraits.info
- sha1828f62be77939b3c738b6fcf43c2d308b59481f6LNK sample with C2 deracefight.info
- sha185cf831025122ab3f411cd21b825eef4d6322b3dLNK sample with C2 bigfrogs.info
- sha18a3889be09bab729a916b97ebbfda19afef828b7LNK sample with C2 checkphoto-bookin.com
- sha18e0e6e3ef3adf32db8ab3826377e0da7e8adb815LNK sample with C2 photo-26653.cfd
- sha18f0d6abefd133bd130c6fb897c764f199a08444cLNK sample with C2 photobookadm.pro
- sha1932f4b274e6f08c55b64a4e7a0cbbe9dff829649LNK sample with C2 tracerecord.info
- sha1954a7dc750ac502c51dfd7db2068a11961b2f342LNK sample with C2 lastnight.info
- sha19b7fcaed4634dd918a26352f12a26f04c52be3a1LNK sample with C2 safegallery.info
- sha19dd1ff00c45da21a2eb57f612f7da5dfe57738f0LNK sample with C2 photo-27657.cfd
- sha1a47ce3551596100173879d406d75b5f960d25c02LNK sample with C2 photohotels-visit.cloud
- sha1a5077656e98906385bea101548b462322cd947faLNK sample with C2 flamecube.info
- sha1a544e8b67f0989f89b556c61fedd67a84c7b1ae6LNK sample with C2 photobookadm.pro
- sha1a56e3014116435cb8b928e33b16ac43f18beb733LNK sample with C2 tracerecord.info
- sha1aa70a6966cf3c430b768977cabdeb8aa2c2b39a3LNK sample with C2 lightsnow.info
- sha1aebce6479d7d5d0d7b59a3da020969ee465f8d36LNK sample with C2 bigfrogs.info
- sha1b0f937a64f64d30fc341b23971ce7682ca725d9eLNK sample with C2 strayweirds.info
- sha1b196b2552a18b8112b72ed7aab4e8ddb1253a81eLNK sample with C2 tracerecord.info
- sha1b255bda9419d919501ae89fadab3ba54e5c0e86bLNK sample with C2 lastnight.info
- sha1b33043882bf31fa05a27243240361478e88963c0LNK sample with C2 marmoteilefinance.com
- sha1b3cefdff102b9984748ce3a94d67a76567a92e1bLNK sample with C2 bubblekip.info
- sha1b6457f1e62be6d8121281a74b0eb75213a849be4LNK sample with C2 lastnight.info
- sha1b6aab844ee021a684ebc236c1815e0d14ef15104LNK sample with C2 tracerecord.info
- sha1b75d84cc997bfcc8e0f03b091e067a74030b29ceLNK sample with C2 photo-62454.cfd
- sha1b82652f33d382a96d9ab5f60dc7a6897dd0f5dfdLNK sample with C2 photo-pagebook.info
- sha1b8d6bb8bf3291fdb3424abbf237f191c9db67a7cLNK sample with C2 lastnight.info
- sha1b9205e4cc92be77dfd4c8767f86384a36520e331LNK sample with C2 dsjkaksfks324das.com
- sha1bd80fa9a88e0b201dbd0e1814d5884c6ac011e5bLNK sample with C2 photo-26656.cfd
- sha1be6494df5052cb6beffaef98a9cc063db0b9a1d4LNK sample with C2 jsdakksd283ksl.com
- sha1c45a08b8bfa12241865dc82b417a29dbc2510a54LNK sample with C2 confbookphoto.info
- sha1c881d5fc0c8debcf17e869f863b50a8016674a70LNK sample with C2 lastnight.info
- sha1c8f0d1447c6d3304b0f4d7e24bdd41b073f5e852LNK sample with C2 tracerecord.info
- sha1cb1820283981c6f32db15d4220b8b8d39da5fc9aLNK sample with C2 photobookadm.pro
- sha1d0fd605b18d8af766fb7beb94f3ef7397db4aa8aLNK sample with C2 hubsecure.info
- sha1d6ffd15c58edac8cf0f5f829b6e248e2d933aa80LNK sample with C2 checkphoto-bookin.com
- sha1d807a3f8dff4f9b8dc828b3e0ef56f85534a91d8LNK sample with C2 lastnight.info
- sha1db68cbf2359df9835a9f85b29ec01e750e814e8bLNK sample with C2 book-imagegallery.info
- sha1ded8575d8badffea8beaa2bbfcb364901b89065dLNK sample with C2 photobookadm.pro
- sha1df5197155515d5f706ecb9b2b326e11d9ed215edLNK sample with C2 photobookadm.pro
- sha1e086583b8bd11a5a146e522f5ac8d8ac68111f44LNK sample with C2 photo-26654.cfd
- sha1e792d6b848af9ed81d98a15b2d2fc5c80eba321aLNK sample with C2 lightsnow.info
- sha1e924650b4fb36679243e7e511fe8e1b00ab2fe6bLNK sample with C2 checkphoto-bookin.com
- sha1e9488c259d1e047a0ad11d4abf1bfc442f49b992LNK sample with C2 photobookadm.pro
- sha1ee17aabe0180f62278f5bcf2ed887352ced66446LNK sample with C2 photobookadm.pro
- sha1efd4283b06ae8a9555475f91f59a733b7b73ddfaLNK sample with C2 book-imagegallery.info
- sha1f277f060ffcd3fbf34bb98884c8a9fa3f0f57845LNK sample with C2 lastnight.info
- sha1f5161d3f01fdd1acf77ff0808b3f732d9dd3a254LNK sample with C2 fancystraits.info
- sha1fb9e1728a0017321fd74f6f9b860b1d5af05d392LNK sample with C2 photo-26654.cfd
- sha1fe18e053366ab393430d20d7bec523071f97fcc1LNK sample with C2 flamecube.info
- urlhxxps://recordstrace[.]info/5bC6vVOeP9PI3B08Redirect URL from Google Share link that delivers the malicious ZIP archive containing the LNK dropper
- urlhxxps://share[.]google/YLoRYlokrW3iner8rAbused Google Share link used in phishing email to evade email security filtering and redirect to malicious payload
- urlhxxps://tonapi[.]io/v2/blockchain/accounts/0:c66119f0e5635c4380441d7a79baf0c02a0ab7ea6cd78de06507fc5dc2c1a5d9/methods/get_domainTON blockchain API endpoint queried by the backdoor to retrieve the current C2 address via EtherHiding technique
Detection / Hunteropenrouter
What Happened
Attackers are sending fake hotel booking emails to people working in the hospitality industry. The emails contain links that lead to malicious Windows shortcut files disguised as images. When opened, these shortcuts run hidden commands that download and install a backdoor program built on Node.js, a legitimate programming tool. The backdoor is particularly clever because it retrieves its control server address from the TON blockchain (a cryptocurrency network), making it hard to block. The malware can download and run additional malicious programs, disable antivirus protections, and stays on the computer even after reboot. The campaign is actively ongoing with hundreds of samples identified. Organizations should train employees to be suspicious of unexpected booking-related emails and ensure their security tools can detect unusual Node.js activity on employee computers.
Key Takeaways
- Multi-stage attack uses malicious LNK files with bigint arithmetic obfuscation to reconstruct C2 URLs and download next-stage PowerShell payloads
- Malware leverages TON blockchain (EtherHiding technique) to dynamically retrieve C2 addresses, allowing threat actors to update infrastructure without modifying the malware
- Node.js backdoor uses a custom bytecode virtual machine interpreter to evade static analysis and hinder reverse engineering
- Backdoor establishes encrypted WebSocket C2 using ECDH (secp256k1) key exchange with HKDF-derived AES-256-CBC encryption
- Campaign is active with 400+ samples sharing MachineID win-5r0dsv23ed0, distributed via spam emails and public forums targeting the hospitality sector
Affected Systems
- Windows endpoints
- Hospitality sector organizations
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Spam email with booking-themed lure targets hospitality sector, using abused Google Share link to redirect to malicious ZIP download
- Execution: Malicious LNK file disguised as image executes obfuscated PowerShell using bigint arithmetic to reconstruct C2 URL and download next-stage PS1 to %TEMP%
- Defense Evasion: PowerShell payload downloads legitimate node.exe if not present, decrypts AES-128-CBC encrypted JavaScript backdoor, and executes it via node.exe
- Persistence: Run registry key created to launch node.exe with backdoor JS payload at user login in detached hidden mode
- C2: Backdoor queries TON blockchain via TONAPI to retrieve current C2 address (EtherHiding), establishes WebSocket connection with ECDH key exchange and AES-256-CBC encryption
- Impact: Backdoor can download and execute additional PE files, PowerShell, and JavaScript payloads; adds Windows Defender exclusions for downloaded files
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: VirusTotal (sample search query provided)
The article provides a VirusTotal search query (name:photo-.png.lnk OR name:IMG-.png.lnk) for finding similar LNK samples but does not include YARA, Sigma, Snort, Suricata, KQL, SPL, or EQL detection rules.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | Process creation events for PowerShell and node.exe are visible, and registry modifications to Run keys are typically logged. However, the use of legitimate node.exe and obfuscated PowerShell may not trigger behavioral signatures without custom rules. |
| Network Visibility | Medium | WebSocket C2 traffic and TON API requests are visible at the network layer, but C2 domains are Cloudflare-protected and dynamically rotated via blockchain. The initial Google Share redirect may appear as legitimate traffic. |
| Detection Difficulty | Hard | Multiple obfuscation layers (bigint arithmetic, AES encryption, custom bytecode VM), legitimate binary abuse (node.exe), blockchain-based C2 retrieval, and frequent C2 domain rotation make signature-based detection challenging. Behavioral detection requires correlating unusual process chains and network patterns. |
Required Log Sources
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 11 (File Creation)
- Sysmon Event ID 13 (Registry Value Set)
- PowerShell Script Block Logging (Event ID 4104)
- Windows Defender Event Log (Add-MpPreference events)
- DNS resolution logs
- Proxy/web gateway logs for WebSocket and HTTPS traffic
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for node.exe processes with unusual parent processes such as PowerShell or cmd.exe, especially when node.exe is located in user-writable directories like AppData or LocalAppData | Sysmon Event ID 1 (Process Creation) with parent-child process relationships and image path filtering | Execution | Medium - legitimate development environments may run node.exe from user directories, but PowerShell as parent is uncommon in dev workflows |
| Consider hunting for PowerShell commands using bigint arithmetic operations (-band, -shr, modulo with 256) that reconstruct strings, as this is an unusual obfuscation pattern | PowerShell Script Block Logging (Event ID 4104) with keyword matching for bigint type casting and bitwise operations | Initial Execution | Low - legitimate PowerShell rarely uses bigint arithmetic for string construction |
| Consider hunting for network connections to tonapi.io or other TON blockchain API endpoints from endpoints that do not normally access cryptocurrency services | DNS resolution logs, proxy logs, and EDR network connection events | C2 | Low to Medium - some legitimate users may access TON blockchain APIs, but it is uncommon in enterprise environments |
| Consider hunting for Add-MpPreference cmdlet usage to add Windows Defender exclusions, especially for files in TEMP or user-writable directories | PowerShell Script Block Logging (Event ID 4104), Windows Defender Operational log | Defense Evasion | Low - legitimate use of Add-MpPreference is rare and typically only done by IT administrators |
| Consider hunting for LNK files matching naming patterns photo-.png.lnk or IMG-.png.lnk, or LNK files with shared MachineID win-5r0dsv23ed0 | File creation events, endpoint file inventory, VirusTotal intelligence matching | Initial Execution | Low - these specific naming patterns for LNK files are highly suspicious |
Control Gaps
- Traditional signature-based AV may miss the backdoor due to custom bytecode VM interpreter and heavy obfuscation
- Network-based detection may fail since C2 domains are Cloudflare-protected and dynamically rotated via TON blockchain
- Email security filtering may be bypassed through Google Share link abuse for initial delivery
- Application allowlisting may not cover node.exe if it is a legitimate development tool in the environment
- Blockchain-based C2 retrieval via TONAPI is unlikely to be blocked by standard web filtering policies
Key Behavioral Indicators
- node.exe process spawned by powershell.exe with command-line arguments containing .js file paths
- PowerShell commands containing [bigint] type casting combined with -band or -shr operators
- Registry modifications to HKCU:\Software\Microsoft\Windows\CurrentVersion\Run referencing node.exe
- node.exe executing from %AppData%\Nodejs\ directory path
- Network connections to tonapi.io/v2/blockchain/accounts/ endpoints from non-developer workstations
- WebSocket connections (wss://) to recently registered domains with .shop, .bond, .sbs, .cfd, or .info TLDs
- Add-MpPreference cmdlet execution adding exclusions for files in %TEMP% directory
- LNK files with icons from shell32.dll masquerading as image files (photo-.png.lnk, IMG-.png.lnk)
False Positive Assessment
Low - The combination of node.exe executing from AppData with PowerShell parentage, bigint obfuscation in PowerShell, TON blockchain API queries, and the specific LNK filename patterns create a highly specific detection profile with minimal legitimate use cases in enterprise environments.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified C2 domains and TON blockchain API endpoint at your web proxy or firewall, and searching endpoint telemetry for any matching SHA1 hashes, LNK filename patterns, or node.exe processes launched from user-writable directories.
- If your EDR supports host isolation, consider isolating any endpoints exhibiting node.exe execution from AppData paths with PowerShell parent processes, and collect forensic artifacts including the dropped JS payload and registry Run key entries.
- Consider searching email gateway logs for Google Share links (share.google) combined with booking-themed lures targeting hospitality staff, and quarantine matching messages.
Infrastructure Hardening
- Evaluate whether blocking tonapi.io and other TON blockchain API endpoints at your web proxy is appropriate for your environment, if these services are not required for business purposes.
- Consider implementing DNS filtering or proxy rules for recently registered domains with suspicious TLDs (.shop, .bond, .sbs, .cfd) especially when accessed via WebSocket protocols.
- If supported by your email security platform, consider enhancing URL rewriting and sandboxing for Google Share links to detect redirect chains to malicious infrastructure.
User Protection
- Consider deploying EDR detection rules for node.exe processes executing from user-writable directories (AppData, LocalAppData, TEMP) with PowerShell parent processes, if your EDR supports custom behavioral rules.
- Evaluate whether application allowlisting can restrict node.exe execution to approved directories and signed binaries, if applicable to your environment.
- Consider monitoring for Add-MpPreference cmdlet usage and alert on any Windows Defender exclusion additions for user-writable paths.
Security Awareness
- Consider incorporating booking-themed phishing lures into existing security awareness training programs, especially for hospitality-sector staff.
- Remind employees to verify unexpected booking confirmations or reservation links through official channels rather than clicking embedded links.
- Consider advising staff to report any unexpected ZIP file downloads or prompts to open image files that are actually Windows shortcut (.lnk) files.
MITRE ATT&CK Mapping
Initial Access
Execution
Persistence
Stealth
Additional IOCs
- Domains:
zloapobikahy23[.]bond- C2 domain retrieved from TON blockchain transaction history (Feb 20, 2026)hsaertyuoang34[.]sbs- C2 domain retrieved from TON blockchain transaction history (Feb 10, 2026)amanohuguta[.]cfd- C2 domain retrieved from TON blockchain transaction history (Feb 7, 2026)flamecube[.]info- C2 domain observed in LNK samplesbigfrogs[.]info- C2 domain observed in LNK sampleshubsecure[.]info- C2 domain observed in LNK samplestracerecord[.]info- C2 domain observed in LNK samplesbubblekip[.]info- C2 domain observed in LNK samplescheckphoto-bookin[.]com- C2 domain observed in LNK samplesstrayweirds[.]info- C2 domain observed in LNK sampleshotelphotoadm[.]info- C2 domain observed in LNK samplesmarmoteilefinance[.]com- C2 domain observed in LNK samplesfancystraits[.]info- C2 domain observed in LNK samplesbook-photopage[.]info- C2 domain observed in LNK samplesjsdakksd283ksl[.]com- C2 domain observed in LNK samplesphoto-pagebook[.]info- C2 domain observed in LNK sampleskeysrace[.]info- C2 domain observed in LNK samplesfellshow[.]info- C2 domain observed in LNK sampleslightsnow[.]info- C2 domain observed in LNK samplesbook-imagegallery[.]info- C2 domain observed in LNK samplesderacefight[.]info- C2 domain observed in LNK samplesdsjkaksfks324das[.]com- C2 domain observed in LNK samplesphoto-26654[.]cfd- C2 domain observed in LNK samplesphoto-27657[.]cfd- C2 domain observed in LNK samplesphoto-26653[.]cfd- C2 domain observed in LNK samplesphoto-132454[.]cfd- C2 domain observed in LNK samplesphoto-26656[.]cfd- C2 domain observed in LNK samplesphoto-62454[.]cfd- C2 domain observed in LNK samplesconfbookphoto[.]info- C2 domain observed in LNK samplesaboutbookphoto[.]pro- C2 domain observed in LNK samplesdancamp[.]info- C2 domain observed in LNK samplesvault-docs-x[.]info- C2 domain observed in LNK samplesphotohotels-visit[.]cloud- C2 domain observed in LNK samplesreplyjoke[.]info- C2 domain observed in LNK samplessafegallery[.]info- C2 domain observed in LNK sampleshaddjskak827sja[.]com- C2 domain observed in LNK samples
- File Hashes:
3d84d37393e244a76c24dfd9eebd0d20914166e6(SHA1) - LNK sample with C2 photobookadm.proa5077656e98906385bea101548b462322cd947fa(SHA1) - LNK sample with C2 flamecube.infoaebce6479d7d5d0d7b59a3da020969ee465f8d36(SHA1) - LNK sample with C2 bigfrogs.infoe9488c259d1e047a0ad11d4abf1bfc442f49b992(SHA1) - LNK sample with C2 photobookadm.prod0fd605b18d8af766fb7beb94f3ef7397db4aa8a(SHA1) - LNK sample with C2 hubsecure.infoded8575d8badffea8beaa2bbfcb364901b89065d(SHA1) - LNK sample with C2 photobookadm.prob6aab844ee021a684ebc236c1815e0d14ef15104(SHA1) - LNK sample with C2 tracerecord.info5daab9743a4c80415d7261d2c2b3720140890e2b(SHA1) - LNK sample with C2 photobookadm.prob3cefdff102b9984748ce3a94d67a76567a92e1b(SHA1) - LNK sample with C2 bubblekip.infod6ffd15c58edac8cf0f5f829b6e248e2d933aa80(SHA1) - LNK sample with C2 checkphoto-bookin.comee17aabe0180f62278f5bcf2ed887352ced66446(SHA1) - LNK sample with C2 photobookadm.pro5c21735b6a823a85730b03a71fe339082c417732(SHA1) - LNK sample with C2 strayweirds.info399712edc298a35e2cb643353b7fcfe4327e173b(SHA1) - LNK sample with C2 bigfrogs.infofe18e053366ab393430d20d7bec523071f97fcc1(SHA1) - LNK sample with C2 flamecube.info69b570e6aa1d50e4bbd89c653eb1b97dab77f174(SHA1) - LNK sample with C2 photobookadm.pro5c80d4af9e9251f2303b88c51435dba09b24177a(SHA1) - LNK sample with C2 hotelphotoadm.infob33043882bf31fa05a27243240361478e88963c0(SHA1) - LNK sample with C2 marmoteilefinance.comb6457f1e62be6d8121281a74b0eb75213a849be4(SHA1) - LNK sample with C2 lastnight.infoc881d5fc0c8debcf17e869f863b50a8016674a70(SHA1) - LNK sample with C2 lastnight.infof5161d3f01fdd1acf77ff0808b3f732d9dd3a254(SHA1) - LNK sample with C2 fancystraits.info0cae9af236ae7ebbb072b058bb65ea6ed7592aae(SHA1) - LNK sample with C2 book-photopage.info18949de1c7550d93e7d58ba545c2ab9703e47d51(SHA1) - LNK sample with C2 jsdakksd283ksl.com0a0378a8e1b2bcf2a6d71ee8d39572897a48ab46(SHA1) - LNK sample with C2 lastnight.info0993e576ea97208db8cd9ee651f6eb6382a6565a(SHA1) - LNK sample with C2 photobookadm.pro18a720ebe0bc1ea1aeea9b495b419cc929c427aa(SHA1) - LNK sample with C2 photo-pagebook.info27a7c5f0dcaf9ed18aa41340aa95d4d5778d7708(SHA1) - LNK sample with C2 keysrace.info4c98348b9bc57485d0624a5fc7838372566aacd7(SHA1) - LNK sample with C2 photobookadm.pro2f9d50d3b166a667fe6b7a05da7039a8029c79b3(SHA1) - LNK sample with C2 fellshow.info307c3a41a56e67ff6d3026c3cd6e35b751f1eafb(SHA1) - LNK sample with C2 lastnight.info2aab7ce372244d0ad882c45cc76579f570d5993b(SHA1) - LNK sample with C2 bigfrogs.info8a3889be09bab729a916b97ebbfda19afef828b7(SHA1) - LNK sample with C2 checkphoto-bookin.comcb1820283981c6f32db15d4220b8b8d39da5fc9a(SHA1) - LNK sample with C2 photobookadm.pro8f0d6abefd133bd130c6fb897c764f199a08444c(SHA1) - LNK sample with C2 photobookadm.proc8f0d1447c6d3304b0f4d7e24bdd41b073f5e852(SHA1) - LNK sample with C2 tracerecord.info625cdb454461e7e82ba9b73028ddbdcbf0b5a7ab(SHA1) - LNK sample with C2 photobookadm.proaa70a6966cf3c430b768977cabdeb8aa2c2b39a3(SHA1) - LNK sample with C2 lightsnow.info2cab6043e2cf54bb1b46357798fba2d8d0d62e77(SHA1) - LNK sample with C2 book-photopage.info6a0bf6e890b24870597befcb447693a598fbd897(SHA1) - LNK sample with C2 hotelphotoadm.info85cf831025122ab3f411cd21b825eef4d6322b3d(SHA1) - LNK sample with C2 bigfrogs.infoa544e8b67f0989f89b556c61fedd67a84c7b1ae6(SHA1) - LNK sample with C2 photobookadm.prob0f937a64f64d30fc341b23971ce7682ca725d9e(SHA1) - LNK sample with C2 strayweirds.info435b00e224f2e001018ed52aff2bd35706614297(SHA1) - LNK sample with C2 keysrace.infobe6494df5052cb6beffaef98a9cc063db0b9a1d4(SHA1) - LNK sample with C2 jsdakksd283ksl.coma56e3014116435cb8b928e33b16ac43f18beb733(SHA1) - LNK sample with C2 tracerecord.info0451e7e75af3c2917a38753db2642619b8f4a0fd(SHA1) - LNK sample with C2 bokconfphoto.info7e05edb4a326c6b80ca937d602d43590bb73d68c(SHA1) - LNK sample with C2 fancystraits.infof277f060ffcd3fbf34bb98884c8a9fa3f0f57845(SHA1) - LNK sample with C2 lastnight.infodb68cbf2359df9835a9f85b29ec01e750e814e8b(SHA1) - LNK sample with C2 book-imagegallery.info828f62be77939b3c738b6fcf43c2d308b59481f6(SHA1) - LNK sample with C2 deracefight.info0ddc606b48c4dd85cad09ffcb2fe560f68e63868(SHA1) - LNK sample with C2 deracefight.infob8d6bb8bf3291fdb3424abbf237f191c9db67a7c(SHA1) - LNK sample with C2 lastnight.info54740686b96e9702cc376d6b04f89105d7700408(SHA1) - LNK sample with C2 bigfrogs.info4d901d5bd6c467f4bedfb0b968eb4c42902cf588(SHA1) - LNK sample with C2 keysrace.infod807a3f8dff4f9b8dc828b3e0ef56f85534a91d8(SHA1) - LNK sample with C2 lastnight.infob9205e4cc92be77dfd4c8767f86384a36520e331(SHA1) - LNK sample with C2 dsjkaksfks324das.comb196b2552a18b8112b72ed7aab4e8ddb1253a81e(SHA1) - LNK sample with C2 tracerecord.info11838c2e3134991402e40a1744aa4c1f93447407(SHA1) - LNK sample with C2 photobookadm.prob82652f33d382a96d9ab5f60dc7a6897dd0f5dfd(SHA1) - LNK sample with C2 photo-pagebook.infofb9e1728a0017321fd74f6f9b860b1d5af05d392(SHA1) - LNK sample with C2 photo-26654.cfd5a944255ee92ba70654d6ed73a52b5de22942340(SHA1) - LNK sample with C2 hotelphotoadm.info7ae18cb6532f2ebb0b6231509541118b52583dc0(SHA1) - LNK sample with C2 photobookadm.proe924650b4fb36679243e7e511fe8e1b00ab2fe6b(SHA1) - LNK sample with C2 checkphoto-bookin.com717e816d99377e285f894457d7a662d85f39053f(SHA1) - LNK sample with C2 fancystraits.infob255bda9419d919501ae89fadab3ba54e5c0e86b(SHA1) - LNK sample with C2 lastnight.info65b2a34be17b3d31221d55f9829f7d876634eaed(SHA1) - LNK sample with C2 tracerecord.info17abeb78bb862d702d4e63d746c58d2d805d71ee(SHA1) - LNK sample with C2 haddjskak827sja.com33f6d432464c20bbdf019f62510435e9a45e29bc(SHA1) - LNK sample with C2 photo-27657.cfd11b2f77a7abf1593648bbcc5bdeb27c4f890aef3(SHA1) - LNK sample with C2 photo-26654.cfd4e3baea41d73967aac96b3cb6525b9edb0ccacd8(SHA1) - LNK sample with C2 strayweirds.infoe086583b8bd11a5a146e522f5ac8d8ac68111f44(SHA1) - LNK sample with C2 photo-26654.cfd932f4b274e6f08c55b64a4e7a0cbbe9dff829649(SHA1) - LNK sample with C2 tracerecord.info0b6e6d9c0091b1f8580bee455eb2199a4fe8a7e0(SHA1) - LNK sample with C2 photobookadm.pro206810a3effe5e477ffc441731b58f7f6cd2c04b(SHA1) - LNK sample with C2 checkphoto-bookin.comb75d84cc997bfcc8e0f03b091e067a74030b29ce(SHA1) - LNK sample with C2 photo-62454.cfd7ba0659c3c33ff97a3c8e10a304b26a58f450b4e(SHA1) - LNK sample with C2 flamecube.info954a7dc750ac502c51dfd7db2068a11961b2f342(SHA1) - LNK sample with C2 lastnight.infoc45a08b8bfa12241865dc82b417a29dbc2510a54(SHA1) - LNK sample with C2 confbookphoto.info6145aabf54337e633670aa2e82835fae97612a5d(SHA1) - LNK sample with C2 aboutbookphoto.pro4edec9cff71c5467808c0a919ba05f13489d21ab(SHA1) - LNK sample with C2 dancamp.infodf5197155515d5f706ecb9b2b326e11d9ed215ed(SHA1) - LNK sample with C2 photobookadm.proefd4283b06ae8a9555475f91f59a733b7b73ddfa(SHA1) - LNK sample with C2 book-imagegallery.info27e1eeb34bd8bd4b54760f15c88dd33f58507e09(SHA1) - LNK sample with C2 lastnight.info391485c342138e8d137d88f927423eb5d7c00ad6(SHA1) - LNK sample with C2 vault-docs-x.info5edc16ff32ff12ee2bf0abbc85a62b93eddab3b3(SHA1) - LNK sample with C2 photobookadm.proa47ce3551596100173879d406d75b5f960d25c02(SHA1) - LNK sample with C2 photohotels-visit.cloud194fb8cbab8b030944e9a1ec44f2e4383f394589(SHA1) - LNK sample with C2 replyjoke.infobd80fa9a88e0b201dbd0e1814d5884c6ac011e5b(SHA1) - LNK sample with C2 photo-26656.cfd0d9796ccb481b09bd92bbe1d7719d0939f645514(SHA1) - LNK sample with C2 photo-132454.cfd8e0e6e3ef3adf32db8ab3826377e0da7e8adb815(SHA1) - LNK sample with C2 photo-26653.cfde792d6b848af9ed81d98a15b2d2fc5c80eba321a(SHA1) - LNK sample with C2 lightsnow.info9dd1ff00c45da21a2eb57f612f7da5dfe57738f0(SHA1) - LNK sample with C2 photo-27657.cfd582cd134c017435b027a2fea86f4e584d69a214f(SHA1) - LNK sample with C2 photobookadm.pro9b7fcaed4634dd918a26352f12a26f04c52be3a1(SHA1) - LNK sample with C2 safegallery.info3c908051cdef94e60b6f444e8719d291a57a2941(SHA1) - LNK sample with C2 marmoteilefinance.com42b40f25d025f23e42aa44f98466ce08bf022f26(SHA1) - LNK sample with C2 photobookadm.pro5a14c0a131c4e5a729a28556b119876651a4047f(SHA1) - LNK sample with C2 photobookadm.pro6f171cc3fe263ff8257c4a8cc38b1cf71fd46343(SHA1) - LNK sample with C2 photobookadm.pro37b61fb43cf3aee0c0c6b3347abd018fc5eb0a5c(SHA1) - LNK sample with C2 photobookadm.pro
- Registry Keys:
HKCU:\Software\Microsoft\Windows\CurrentVersion\Run- Run registry key used for persistence; value launches node.exe with backdoor JS payload at user login
- File Paths:
%AppData%\Nodejs\node-v24.13.0-win-x64\node.exe- Dropped legitimate Node.js runtime used to execute the backdoor JS payload%TEMP%\4eCBBP.ps1- Downloaded PowerShell next-stage payload from LNK dropper (variant 1)%TEMP%\ZhXlZHF.ps1- Downloaded PowerShell next-stage payload from LNK dropper (variant 2)
- Command Lines:
- Purpose: LNK dropper executes obfuscated PowerShell to reconstruct C2 URL via bigint subtraction and bitwise operations, then downloads and executes next-stage PS1 payload | Tools:
powershell.exe| Stage: Initial Execution |powershell -ep bypass -c - Purpose: Node.js runtime executes the decrypted JavaScript backdoor payload with C2 address as argument | Tools:
node.exe| Stage: Execution |node.exe <JS payload> <C2> - Purpose: PowerShell command to enumerate running node.exe processes matching the dropped runtime path to prevent multiple backdoor instances | Tools:
powershell.exe| Stage: Execution |powershell.exe -c "(Get-Process | Where-Object - Purpose: PowerShell command creating a Run registry key for persistence that launches node.exe with backdoor JS in detached hidden mode | Tools:
powershell.exe| Stage: Persistence |Set-ItemProperty -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run" - Purpose: PowerShell command adding Windows Defender exclusion for a downloaded payload file path before execution | Tools:
powershell.exe| Stage: Defense Evasion |Add-MpPreference -ExclusionProcess
- Purpose: LNK dropper executes obfuscated PowerShell to reconstruct C2 URL via bigint subtraction and bitwise operations, then downloads and executes next-stage PS1 payload | Tools:
- Other:
rMN0KExxu9f3CaWamcq6g/l+rd2rY/fwye18Ca5G9z0=- Base64-encoded AES-128-CBC key used to decrypt the Node.js backdoor payloadSw9v7WJhr+I8JVU04YASYw==- Base64-encoded AES-128-CBC IV used to decrypt the Node.js backdoor payload