Mark RadarMARK RADAR
EN
Event File CRYPTO Phishing

Hackers Use TON Blockchain to Target Japanese Hotels

1 reports · First detected 2026-07-02 · Last active 2026-07-02

Japanese hotels and guesthouses rely heavily on booking platforms such as Booking.com to handle customer complaints and reservations, making employees less wary of related emails. The campaign targets accommodation providers with fake platform notifications that install the TONResolver remote-access trojan. It marks the first known use of The Open Network, or TON, blockchain by hackers to conceal malicious communications infrastructure.

The newly disclosed attack chain begins with phishing emails disguised as Booking.com customer complaints, which trick Japanese hotel employees into running malicious files. TONResolver then uses TON to establish command-and-control, or C2, communications and allows the attackers to change back-end server addresses at any time. Reports did not disclose the exact attack dates, the number of affected hotels, the scale of any data breach or the amount of financial losses.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR