|
||
|
||
Microsoft Threat Intelligence recently uncovered an active multistage intrusion campaign targeting organizations in the hospitality and hotel industry in Europe and Asia, particularly Japan, since April 2026.
The unknown threat actors used photo-themed ZIP archives that users were tricked into downloading. These archives contained fake image shortcut files that, when launched, started an attack chain that relied on an obfuscated PowerShell script, a Node.js-based implant, dual registry persistence, and C&C communications over nonstandard ports. In addition, the campaign’s postcompromise activities included C&C beaconing, forced shutdowns, and a compilation of PE payloads. While its ultimate objective remained unclear, the researchers believed the fact that obfuscation and persistence were ensured could indicate they were preparing the infected devices for more follow-on activities.
The threat actors also misused legitimate services like Calendly’s email notification infrastructure and Google’s URL redirect functionality to deliver phishing emails with multilingual lures and subject lines. These emails attempted to bypass conventional authentication checks through authentication laundering.
The researchers identified 78 network IoCs comprising 73 domains and five IP addresses in their report. After filtering out a domain owned by a legitimate entity aided by the WhoisXML API MCP Server, we were left with 77 IoCs for further analysis.
Our own investigation of the threat led to these discoveries:
A sample of the additional artifacts obtained from our analysis is available for download from our website.
We began our DNS deep dive by looking more closely at the 72 domain IoCs.
First, we learned from sample network traffic data from the IASC that two unique client IP addresses under two distinct ASNs communicated with three of the domain IoCs—photo-26653[.]cfd, photo-26656[.]cfd, and photo-27857[.]cfd—via six DNS queries recorded between 3 and 13 June 2026.

Next, we learned that five domain IoCs appeared in four typosquatting groups based on the results of our Typosquatting API queries.

Take a look at more details below.
| DOMAIN IoC | GROUP NUMBER ID | GROUP MEMBER NUMBER | GROUP MEMBERS OTHER THAN THE IoCs | CREATION DATE |
|---|---|---|---|---|
| photo-132454[.]cfd created on 05/28/26 | 5601 | 5 | photo-432454[.]cfd photo-532454[.]cfd photo-332454[.]cfd photo-232454[.]cfd | 05/28/26 05/28/26 05/28/26 05/28/26 |
| photo-21473[.]xyz created on 05/15/26 | 5333 | 4 | photo-41473[.]xyz photo-51473[.]xyz photo-31473[.]xyz | 05/15/26 05/15/26 05/15/26 |
| photo-26654[.]cfd and photo-26254[.]cfd created on 05/31/26 | 3103 | 4 | photo-26554[.]cfd photo-26154[.]cfd | 05/31/26 05/31/26 |
| photo-8632454[.]cfd created on 05/27/26 | 4487 | 6 | photo-3632454[.]cfd photo-1632454[.]cfd photo-4632454[.]cfd photo-7632454[.]cfd photo-6632454[.]cfd | 05/27/26 05/27/26 05/27/26 05/27/26 05/27/26 |
The First Watch Malicious Domains Data Feed also provided interesting findings. We discovered that the domain IoC—zloapobikahy23[.]bond—created on 20 February 2026 was likely registered with malicious intent. It was dubbed as such 125 days prior to when it was declared an IoC on 25 June 2026.
We then queried the domain IoCs on WHOIS API and discovered that:

They were administered by six registrars.

While three domain IoCs did not have registrant countries on record, the remaining 69 were registered in three countries.

Finally, we queried the domain IoCs on DNS Chronicle API and found out that all 72 recorded 981 historical domain-to-IP resolutions over time. Here are more details for five examples.
| DOMAIN IoC | NUMBER OF DOMAIN-TO-IP RESOLUTIONS | DATES SEEN |
|---|---|---|
| heliosup[.]info | 142 | 02/28/20–05/14/26 |
| haobbao[.]com | 115 | 06/25/18–05/19/26 |
| lestresot[.]info | 16 | 04/02/26–05/25/26 |
| visaphoto-secure[.]info | 16 | 04/16/26–05/26/26 |
| photo-box[.]info | 13 | 02/06/17–05/28/26 |
While 71 domain IoCs were registered in 2026 as mentioned earlier, only 69 started posting domain-to-IP resolutions this year. That could indicate that the registrations of two of the relatively new domain IoCs lapsed and they were recently reregistered.
Now, on to the five IP IoCs.
First, sample network traffic data from the IASC showed that 2,357 unique IP addresses potentially owned by victims under 114 distinct ASNs communicated with the five IP IoCs between 31 December 2025 and 28 June 2026.

Next, we queried the IP IoCs on Bulk IP Geolocation Lookup and learned that:

While two did not have ISPs on record, the remaining three were administered by three ISPs.

Finally, our DNS Chronicle API query results for the IP IoCs revealed that only three recorded historical IP-to-domain resolutions over time—1,101 to be exact. The IP IoC 172[.]67[.]161[.]215, for instance, posted 1,000 resolutions from 26 May to 27 November 2020.
After learning more about the network IoCs, we jumped off them to uncover new possibly connected artifacts.
First, we queried the domain IoCs on WHOIS History API and learned that 23 had 75 email addresses in their historical records. Upon closer examination, we determined that 12 were public email addresses.
We then queried the public email addresses on Reverse WHOIS API and discovered that four could belong to domainers, hence their exclusion from further analysis. The remaining eight public email addresses, meanwhile, led to the discovery of 2,840 unique email-connected domains after those already dubbed as IoCs.
Next, we queried the email-connected domains on Threat Intelligence API and found out that 26 have already been weaponized for various threats.
This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.
Sponsored byDNIB.com
Sponsored byIPv4.Global
Sponsored byVerisign
Sponsored byRadix
Sponsored byVerisign
Sponsored byCSC
Sponsored byWhoisXML API