started · updated
Andorra cybersecurity agency warns of hotel sector phishing attacks
The National Cybersecurity Agency of Andorra (ANC-AD) has issued an alert regarding an active spear-phishing campaign targeting the country's hotel sector, specifically focusing on reception staff. At least one computer has already been confirmed as infected.
The attackers send emails in English from free messaging accounts, impersonating guests who claim to have been physically assaulted by hotel staff. These messages threaten legal action if a response is not received within 48 hours. The emails contain links that utilize legitimate Google infrastructure to redirect victims to attacker-controlled domains. Once accessed, a compressed file is downloaded containing malware disguised as a photograph.
ANC-AD describes the campaign as highly sophisticated and high-impact. The malware generates different code for each download to evade signature-based detection tools, and the server only delivers the file to specific browsers and operating systems to complicate technical analysis. The agency advises hotels to notify staff, review reservation and contact inboxes, and verify all compressed files with IT departments before opening them.
Entities
Agència Nacional de Ciberseguretat d’Andorra · Andorra · Google