[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOtdOyt9_nlYDtIDiDtCHyk4vhQ164EGlKZm-Lj4HT_o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"8ba34424-9e3a-4c39-9509-1f0f7e97c33a","phishing-campaigns-use-zip-files-and-blockchain-to-persist-in-hospitality-orgs","9d5a2c33-4088-4818-8dae-505a6ce8ffd7","Phishing Campaigns Use Zip Files and Blockchain to Persist in Hospitality Orgs","Attackers are targeting hospitality organizations in the EU and Asia through carefully crafted phishing emails delivering malicious zip files, exploiting employees' trust and routine workflows. The use of obfuscation techniques makes the malware difficult to detect by traditional security tools, while leveraging blockchain services for command-and-control provides resilience against takedowns. This matters because the hospitality sector handles vast amounts of sensitive guest and payment data, making it a high-value target. The combination of social engineering and advanced evasion techniques highlights the critical need for both technical defenses and a well-trained workforce.","**Immediate actions:**\n- Block or quarantine all unexpected zip and archive file attachments at the email gateway before delivery to end users.\n- Restrict outbound connections to known blockchain and decentralized service endpoints via firewall or DNS filtering rules.\n- Issue an urgent security awareness advisory to hospitality staff detailing the specific phishing tactics used in these campaigns.\n\n**Long-term improvements:**\n- Implement a formal security awareness training program with quarterly phishing simulations tailored to hospitality sector scenarios.\n- Enforce application whitelisting to prevent unauthorized executables extracted from malicious archives from running.\n- Establish and regularly test an incident response playbook specifically covering phishing-delivered malware scenarios.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tooling configured to flag obfuscated script execution and anomalous process behavior.\n- Enable centralized SIEM logging for all email gateway events, endpoint alerts, and unusual outbound network traffic to non-standard services.\n- Monitor DNS query logs for connections to blockchain or decentralized infrastructure that may indicate active C2 communication.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 9 – Email and Web Browser Protections","CIS Control 14 – Security Awareness and Skills Training","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-61 – Incident Response","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 AT-2 – Security Awareness Training","NIST SP 800-53 SC-7 – Boundary Protection","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","MITRE ATT&CK T1566.001 – Phishing: Spearphishing Attachment","MITRE ATT&CK T1027 – Obfuscated Files or Information","MITRE ATT&CK T1102 – Web Service (Blockchain C2)","published","2026-07-01T06:21:59.452101+00:00","2026-07-01T06:21:59.171+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fphishers-persistence-eu-asia-hospitality-orgs","phishers-gain-persistence-at-eu-asia-hospitality-orgs-aa97ce","Phishers Gain Persistence at EU, Asia Hospitality Orgs",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":45,"name":46,"slug":47,"description":48,"color":49},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]