[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbBlvQC4OCBRKLwPcKHbw-ysFZitRTSiDaDZzbuiQUkk":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":30},"9d5a2c33-4088-4818-8dae-505a6ce8ffd7","Phishers Gain Persistence at EU, Asia Hospitality Orgs","phishers-gain-persistence-at-eu-asia-hospitality-orgs-aa97ce","Separate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.","Two distinct but similar phishing campaigns are targeting hospitality organizations in the EU and Asia. These campaigns leverage malicious zip files delivered via social engineering tactics. The malware employs obfuscation techniques and exploits blockchain services for persistence, making detection and removal more challenging.","Phishers use malicious zip files to spread malware at EU and Asia hospitality organizations.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fphishers-persistence-eu-asia-hospitality-orgs","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt602a68e7af541816\u002F6a43acb31b4f21a79166565a\u002Fhotel-Henk_Vrieselaar-Alamy.jpg?width=720&quality=80&disable=upscale","2026-06-30T18:59:46+00:00","2026-07-01T06:00:20.863603+00:00",7,[18,21,23],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":20},"Trend Micro",{"name":24,"type":25},"blockchain","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":26,"icon":11,"name":28,"slug":29},"Malware","malware",[31,36,38],{"category":32},{"id":33,"icon":11,"name":34,"slug":35},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":37},{"id":26,"icon":11,"name":28,"slug":29},{"category":39},{"id":40,"icon":11,"name":41,"slug":42},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]