Threat Reports

Read other reports

Massive Photo ZIP Campaign Targets Booking.com Partner and Other Hotels across Japan and Europe

Microsoft Threat Intelligence uncovered¹ an active multistage intrusion campaign targeting hospitality and hotel organizations in Europe and Asia, particularly Japan, since April 2026. The unknown threat actors used photo-themed ZIP archives containing fake image shortcut files to launch an attack chain involving obfuscated PowerShell, a Node.js-based implant, registry persistence, and C&C communications. They also misused legitimate services such as Calendly’s email notification infrastructure and Google’s URL redirect functionality to deliver phishing emails.

Microsoft published 78 network IoCs—73 domains and five IP addresses. Using the WhoisXML API MCP Server², we determined that one domain belonged to a legitimate entity and analyzed the remaining 77 IoCs to uncover additional infrastructure and connections related to the campaign.

77

Original IoCs Analyzed

Domain and IP indicators from the reported campaign

Key Findings

2,840

Email-connected domains

123

Additional IP addresses

144

IP-connected domains

95

String-connected domains

These are key highlights from our analysis. The full report contains many more findings and detailed insights.

OUR RESEARCH PROCESS

  • Domain IoC legitimacy check
  • Client traffic and typosquatting analysis
  • Domain IoC WHOIS and DNS history analysis
  • Email-connected domain discovery
  • IP and IP-connected domain discovery
  • String-connected domain discovery

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-access/
  • [2] https://main.whoisxmlapi.com/ai/mcp-server

Latest Reports

Read other reports

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.