Photo ZIP Campaign Hits Hotels With Node.js Implants and Persistent Backdoors

Microsoft Threat Intelligence spotted an active campaign targeting hotels and hospitality companies since April 2026. The attackers are using photo-themed ZIP files and fake image shortcuts to drop a Node.js implant on victims’ machines.

Here’s how it works. A phishing email arrives — often disguised as a guest complaint or room inquiry — with a link to a ZIP file. The archive contains a .LNK file named something like IMG-805916584.png.lnk or PHOTO-215746435.png.lnk. It looks like an image. It’s not.

Click it, and the attack chain kicks off. Obfuscated PowerShell downloads a Node.js backdoor. Registry persistence gets set up. C2 communications happen over non-standard ports.

The phishing emails use a technique Microsoft calls “authentication laundering” — routing through Calendly’s notification infrastructure and Google’s URL redirect to make malicious emails look like legit notifications. Bypasses conventional email auth checks cleanly.

Two waves observed so far. Wave 1 used IMG- prefixed LNK files. Wave 2 switched to PHOTO- and added a new stage where PowerShell triggers dynamic .NET DLL compilation via csc.exe. The attackers expanded domain infrastructure to include .cfd domains behind Cloudflare.

Victims are mostly in Europe and Asia. The targeted user accounts tell the story — reception, frontdesk, reservations, accueil, recepce. People who deal with guest photos and documents daily.

What happens after compromise? C2 beaconing, forced shutdowns, compiling PE payloads on the fly. The ultimate objective isn’t clear yet, but the investment in obfuscation and persistence suggests they’re laying groundwork for something bigger.

No attribution to a known group yet. But the campaign is active and evolving.