Andorra Cybersecurity Agency Warns Hotels of Spear-Phishing Malware Attack
Andorra's National Cybersecurity Agency reports a sophisticated spear-phishing campaign hitting hotel staff with malware-laden links disguised as guest complaints. Preventive measures include inbox scans and IT verification.
Key Points
- ANC-AD confirms active spear-phishing targeting hotel reception staff via fake angry guest emails.
- Malware in disguised photo archives is polymorphic, evading detection by varying on each download.
- Attacks risk exposing confidential data in tourism sector; at least one device infected.
- Hotels urged to check inboxes, avoid attachments, enable file extensions, and report incidents.
Andorra's National Cybersecurity Agency (ANC-AD) has issued an urgent alert about an active spear-phishing campaign targeting hotel reception staff, confirming at least one device infection and urging immediate checks of reservation and contact inboxes.
The attacks involve emails in English sent from free messaging accounts. They impersonate angry guests alleging physical assaults by hotel employees and demanding a response within 48 hours to avoid legal action. Each message contains a link that passes through legitimate Google infrastructure before redirecting to attacker-controlled domains. Clicking leads to a compressed archive download with malware disguised as a photo.
The agency highlighted the campaign's sophistication. The malware is polymorphic, producing unique variants on every download to bypass signature-based detection tools. The malicious server also delivers files selectively to specific browsers and operating systems, dodging routine analysis and organizational protections.
This approach enables attackers to access confidential data, posing a high risk to Andorra's tourism sector. ANC-AD stressed simple preventive steps: hotels must notify reception teams right away, avoid opening compressed attachments without IT checks, enable file extension visibility on reception computers, and verify security protocols with technology providers.
The warning, released on 28 August 2026, calls for swift incident reporting to limit the threat's spread.
Related Articles
Other articles from Catalan-language sources about the same story: