NordVPN Promotion

Home / Industry

Massive Photo ZIP Campaign Targets Booking.com Partner and Other Hotels across Japan and Europe

Microsoft Threat Intelligence recently uncovered an active multistage intrusion campaign targeting organizations in the hospitality and hotel industry in Europe and Asia, particularly Japan, since April 2026.

The unknown threat actors used photo-themed ZIP archives that users were tricked into downloading. These archives contained fake image shortcut files that, when launched, started an attack chain that relied on an obfuscated PowerShell script, a Node.js-based implant, dual registry persistence, and C&C communications over nonstandard ports. In addition, the campaign’s postcompromise activities included C&C beaconing, forced shutdowns, and a compilation of PE payloads. While its ultimate objective remained unclear, the researchers believed the fact that obfuscation and persistence were ensured could indicate they were preparing the infected devices for more follow-on activities.

The threat actors also misused legitimate services like Calendly’s email notification infrastructure and Google’s URL redirect functionality to deliver phishing emails with multilingual lures and subject lines. These emails attempted to bypass conventional authentication checks through authentication laundering.

The researchers identified 78 network IoCs comprising 73 domains and five IP addresses in their report. After filtering out a domain owned by a legitimate entity aided by the WhoisXML API MCP Server, we were left with 77 IoCs for further analysis.

Our own investigation of the threat led to these discoveries:

  • Two unique client IP addresses that communicated with three domain IoCs
  • Five domain IoCs that appeared in four typosquatting groups
  • One domain IoC that was likely registered with malicious intent
  • 2,357 distinct IP addresses potentially belonging to victims that communicated with five IP IoCs
  • 2,840 email-connected domains, 26 confirmed malicious
  • 123 additional IP addresses, all confirmed malicious
  • 144 IP-connected domains
  • 95 string-connected domains

A sample of the additional artifacts obtained from our analysis is available for download from our website.

Photo ZIP Campaign Domain IoCs Dissected

We began our DNS deep dive by looking more closely at the 72 domain IoCs.

First, we learned from sample network traffic data from the IASC that two unique client IP addresses under two distinct ASNs communicated with three of the domain IoCs—photo-26653[.]cfd, photo-26656[.]cfd, and photo-27857[.]cfd—via six DNS queries recorded between 3 and 13 June 2026.

Next, we learned that five domain IoCs appeared in four typosquatting groups based on the results of our Typosquatting API queries.

Take a look at more details below.

DOMAIN IoCGROUP NUMBER IDGROUP MEMBER NUMBERGROUP MEMBERS OTHER THAN THE IoCsCREATION DATE
photo-132454[.]cfd created on 05/28/2656015photo-432454[.]cfd
photo-532454[.]cfd
photo-332454[.]cfd
photo-232454[.]cfd
05/28/26
05/28/26
05/28/26
05/28/26
photo-21473[.]xyz created on 05/15/2653334photo-41473[.]xyz
photo-51473[.]xyz
photo-31473[.]xyz
05/15/26
05/15/26
05/15/26
photo-26654[.]cfd and photo-26254[.]cfd created on 05/31/2631034photo-26554[.]cfd
photo-26154[.]cfd
05/31/26
05/31/26
photo-8632454[.]cfd created on 05/27/2644876photo-3632454[.]cfd
photo-1632454[.]cfd
photo-4632454[.]cfd
photo-7632454[.]cfd
photo-6632454[.]cfd
05/27/26
05/27/26
05/27/26
05/27/26
05/27/26

The First Watch Malicious Domains Data Feed also provided interesting findings. We discovered that the domain IoC—zloapobikahy23[.]bond—created on 20 February 2026 was likely registered with malicious intent. It was dubbed as such 125 days prior to when it was declared an IoC on 25 June 2026.

We then queried the domain IoCs on WHOIS API and discovered that:

  • While a vast majority—71 to be exact—were relatively newly registered, one was notably aged.
  • They were administered by six registrars.

  • While three domain IoCs did not have registrant countries on record, the remaining 69 were registered in three countries.

Finally, we queried the domain IoCs on DNS Chronicle API and found out that all 72 recorded 981 historical domain-to-IP resolutions over time. Here are more details for five examples.

DOMAIN IoCNUMBER OF DOMAIN-TO-IP RESOLUTIONSDATES SEEN
heliosup[.]info14202/28/20–05/14/26
haobbao[.]com11506/25/18–05/19/26
lestresot[.]info1604/02/26–05/25/26
visaphoto-secure[.]info1604/16/26–05/26/26
photo-box[.]info1302/06/17–05/28/26

While 71 domain IoCs were registered in 2026 as mentioned earlier, only 69 started posting domain-to-IP resolutions this year. That could indicate that the registrations of two of the relatively new domain IoCs lapsed and they were recently reregistered.

Photo ZIP Campaign IP IoCs Investigated

Now, on to the five IP IoCs.

First, sample network traffic data from the IASC showed that 2,357 unique IP addresses potentially owned by victims under 114 distinct ASNs communicated with the five IP IoCs between 31 December 2025 and 28 June 2026.

Next, we queried the IP IoCs on Bulk IP Geolocation Lookup and learned that:

  • They were geolocated in three countries, one of which—the U.S.—was also named a registrant country.
  • While two did not have ISPs on record, the remaining three were administered by three ISPs.

Finally, our DNS Chronicle API query results for the IP IoCs revealed that only three recorded historical IP-to-domain resolutions over time—1,101 to be exact. The IP IoC 172[.]67[.]161[.]215, for instance, posted 1,000 resolutions from 26 May to 27 November 2020.

Photo ZIP Campaign New Artifacts Collated

After learning more about the network IoCs, we jumped off them to uncover new possibly connected artifacts.

First, we queried the domain IoCs on WHOIS History API and learned that 23 had 75 email addresses in their historical records. Upon closer examination, we determined that 12 were public email addresses.

We then queried the public email addresses on Reverse WHOIS API and discovered that four could belong to domainers, hence their exclusion from further analysis. The remaining eight public email addresses, meanwhile, led to the discovery of 2,840 unique email-connected domains after those already dubbed as IoCs.

Next, we queried the email-connected domains on Threat Intelligence API and found out that 26 have already been weaponized for various threats.

This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By WhoisXML API, A Domain Research, Whois, DNS, and Threat Intelligence API and Data Provider

Whois API, Inc. (WhoisXML API) is a big data and API company that provides domain research & monitoring, Whois, DNS, IP, and threat intelligence API, data and tools to a variety of industries.

Visit Page

Filed Under

Comments

Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

DNS

Sponsored byDNIB.com

IPv4 Markets

Sponsored byIPv4.Global

Cybersecurity

Sponsored byVerisign

New TLDs

Sponsored byRadix

Domain Names

Sponsored byVerisign

Brand Protection

Sponsored byCSC

DNS Security

Sponsored byWhoisXML API

NordVPN Promotion