Skip to content

TonRAT

TonRAT is a Node.js-based remote access trojan used in phishing campaigns targeting hospitality organizations, particularly hotel operators and front-desk environments in Europe and Asia.

Profile source: Mallory opens in a new tab

TonRAT

Family profile

TonRAT is a Node.js-based remote access trojan used in phishing campaigns targeting hospitality organizations, particularly hotel operators and front-desk environments in Europe and Asia. It has been delivered through booking-themed social engineering lures, including fake guest complaints and bedbug-related messages, with victims redirected to archives containing malicious Windows shortcut files. Execution typically begins with a PowerShell-based loader chain that decrypts an obfuscated JavaScript payload, installs or reuses a legitimate Node.js runtime, and launches the implant in user space.

The malware combines remote access and downloader functionality. It performs host reconnaissance by collecting system and user information, establishes persistence through Windows autorun mechanisms, and communicates with operators over encrypted WebSocket channels. TonRAT supports arbitrary command execution and can download and run additional payloads, enabling broader post-compromise activity. Observed tradecraft also includes defense evasion measures such as heavy JavaScript obfuscation, hidden PowerShell execution, mutex use, and the addition of Microsoft Defender exclusions in some intrusion chains.

A distinctive feature of TonRAT is its use of The Open Network (TON) ecosystem for command-and-control discovery. Rather than relying on a fixed embedded domain, the implant queries a public TON API to retrieve current C2 domain information associated with attacker-controlled blockchain data, allowing operators to rotate infrastructure without rebuilding the malware. After resolving the active endpoint, TonRAT establishes an encrypted session using a key-exchange mechanism and then protects subsequent traffic with symmetric encryption over WebSocket.

TonRAT has been associated with Booking.com-themed phishing operations and broader hospitality-focused intrusion activity observed in 2026. Public reporting has not conclusively attributed the campaign to a named threat actor. The malware’s delivery chain, resilient persistence, dynamic C2 resolution, and support for follow-on payload execution indicate its role as a flexible access platform for sustained compromise of Windows systems.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance

MITRE ATT&CK

TonRAT in ATT&CK

29 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.