Find notable cyber news and cases, enriched with sources, timelines, and signals.

TONResolver RAT delivered via ZIP, LNK, and PowerShell

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The TONResolver malware implant was delivered through a ZIP/LNK/PowerShell chain that can establish a remote access trojan foothold and enable command execution. The payload is tracked as TrojanSpy.JS.TONRESOLVER.A and is designed for follow-on compromise rather than simple nuisance behavior. It also uses the TON blockchain to make command-and-control switching harder to detect and block. The delivery and obfuscation layers raise the cost of inspection, containment, and takedown.

Related Happenings

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

ClickFix payload delivery analysis exposes API-driven generation and Downloads-folder AMSI evasion

Technical Analysis
H score74 First: 01.07.2026 08:32 Last: 01.07.2026 08:32 Sources 1

About this happening: Analysis of ClickFix payload delivery shows operators moving to API-driven servers and a Downloads-folder orchestrator, increasing stealth across live campaigns. The b...

Booking.com partner accommodation phishing campaign targeting Japan

Campaign
H score32 First: 30.06.2026 13:30 Last: 30.06.2026 13:30 Sources 1

How related: Cyber threat actors are targeting employees of Booking.com partner accommodations in Japan, using phishing emails that impersonate guest complaints and review requests to trick hotel staff into executing malicious files.

About this happening: A phishing campaign is targeting Booking.com partner accommodations in Japan with guest-complaint and review-request lures that deliver malicious files for TONResolv...

TonRAT Node.js implant with TON blockchain C2

Malware Activity
H score24 First: 26.06.2026 12:27 Last: 26.06.2026 12:27 Sources 1

About this happening: TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...

OXLOADER loader stages CastleStealer via UAC prompting and DLL side-loading

Malware Activity
H score20 First: 22.06.2026 16:20 Last: 22.06.2026 16:20 Sources 1

About this happening: The OXLOADER malware activity now shows a loader delivering CastleStealer through PowerShell, UAC prompting, and DLL side-loading, giving the stealer a ste...

Timeline

  1. 30.06.2026 13:30 2 articles · 15d ago

    TONResolver RAT delivered via ZIP, LNK, and PowerShell

    Initial Disclosure

    A phishing-delivered ZIP file contained a disguised LNK shortcut that launched TrojanSpy.JS.TONRESOLVER.A through a PowerShell script. That first stage established the malware's initial foothold and set up persistent access for later commands.

    Show sources