Japanese hotels are getting hit through TON-based malware 🦠🏨 Since late May 2026, Japanese hotels and travel agencies have reportedly been targeted by a trojan called TONResolver. The infection path is classic: phishing emails pretending to be from Booking com, with malicious .LNK files attached. After landing on the system, the malware steals credentials from Chrome and Edge, scans the internal network, and opens remote access for attackers. The weird part is the control layer 👀 TONResolver uses TON smart contracts for C2 communication — basically hiding command signals inside blockchain activity. That makes the usual “block the server” playbook much weaker, because the chain itself doesn’t have a simple off switch. And this is not the first time. Earlier in 2026, TrickMo used a similar TON-based setup. Same pattern, same uncomfortable lesson: neutral infrastructure can become a very convenient hiding place when bad actors need something resilient. Blockchains were built to resist shutdowns. Malware operators noticed too TON 24/7 🤑
Japanese hotels are getting hit through TON-based malware 🦠🏨 Since… — TON 24/7 — TG.ME
July 6, 2026 4K 1