A booking-themed phishing wave aimed at hospitality workflows shows how attackers can stack ordinary tools - cloud sharing, ZIP files, LNK shortcuts, PowerShell, and Node.js - into a delivery chain that is harder to spot and block.
A phishing run aimed at hotels in Europe and Asia is using photo-themed ZIP attachments and a Node.js implant, turning ordinary front-desk inboxes into potential entry points.