security: Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
Microsoft Security Blog
2026-06-25
Microsoft Threat Intelligence reported an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The attackers use photo-themed ZIP archives and fake image shortcut files to deploy a persistent Node.js implant and avoid detection.