Microsoft warns of ZIP campaign against hospitality organisations
Microsoft reports an active campaign against hospitality and hotel organisations in Europe and Asia running since April 2026. The phishing lures deliver photo-themed ZIP files containing fake image shortcuts. When opened, the chain runs obfuscated PowerShell, deploys a Node.js implant and establishes dual registry persistence. Command traffic uses non-standard ports, and the attackers abuse legitimate services such as Calendly and Google redirects to make the phishing links appear trustworthy.
What this means for your organisation
Hospitality businesses handle payment cards, passport details and booking histories, and often have high staff turnover among people whose job involves opening attachments from unknown senders. Persistent access to such systems gives the attacker both personal data and a foothold for later extortion. The use of well-known services in the links removes the usual warning signals.
Berigo recommends
- Block or quarantine ZIP attachments containing shortcut files in your mail filtering.
- Monitor for new autostart registry entries and outbound traffic on unusual ports.
- Give reception and booking staff short, concrete training on this type of attachment.
- Map which personal data sits in the booking systems and what a notification to the Norwegian Data Protection Authority would require.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch