Back to all lessons
Awareness Lessons
3 months ago

Phishing Campaigns Use Zip Files and Blockchain to Persist in Hospitality Orgs

Attackers are targeting hospitality organizations in the EU and Asia through carefully crafted phishing emails delivering malicious zip files, exploiting employees' trust and routine workflows. The use of obfuscation techniques makes the malware difficult to detect by traditional security tools, while leveraging blockchain services for command-and-control provides resilience against takedowns. This matters because the hospitality sector handles vast amounts of sensitive guest and payment data, making it a high-value target. The combination of social engineering and advanced evasion techniques highlights the critical need for both technical defenses and a well-trained workforce.

Tactical Insight

Immediate actions

  • Block or quarantine all unexpected zip and archive file attachments at the email gateway before delivery to end users.
  • Restrict outbound connections to known blockchain and decentralized service endpoints via firewall or DNS filtering rules.
  • Issue an urgent security awareness advisory to hospitality staff detailing the specific phishing tactics used in these campaigns.

Long-term improvements

  • Implement a formal security awareness training program with quarterly phishing simulations tailored to hospitality sector scenarios.
  • Enforce application whitelisting to prevent unauthorized executables extracted from malicious archives from running.
  • Establish and regularly test an incident response playbook specifically covering phishing-delivered malware scenarios.

Detection measures

  • Deploy endpoint detection and response (EDR) tooling configured to flag obfuscated script execution and anomalous process behavior.
  • Enable centralized SIEM logging for all email gateway events, endpoint alerts, and unusual outbound network traffic to non-standard services.
  • Monitor DNS query logs for connections to blockchain or decentralized infrastructure that may indicate active C2 communication.