Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
Malware

TONResolver

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

19 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1566PhishingEvidence1

Attackers are targeting employees of Booking.com partner companies in Japan, using phishing emails that impersonate guest complaints and review requests to trick hotel staff into executing malicious files.

T1566.001Spearphishing AttachmentEvidence1

the infection began when the user clicked a shortcut link file (LNK) disguised as a photo file within the zip archive.

T1566.002Spearphishing LinkEvidence1

In this attack, a zip file was downloaded by accessing a hyperlink to a suspicious web site, and the infection began when the user clicked a shortcut link file (LNK) disguised as a photo file within the zip archive.

Execution

3 techniques
T1059.001PowerShellEvidence1

The script then executes Invoke-WebRequest against the reconstructed domain, saves the retrieved PS1 file (PowerShell script file) under "%TEMP%", and executes it with PowerShell.

T1059.007JavaScriptEvidence1

The JavaScript file executed with arguments by node.exe (detection name: TrojanSpy.JS.TONRESOLVER.A) was identified as malware functioning as a remote access trojan (RAT).

T1204User ExecutionEvidence1

The infection begins when a user downloads a zip file via a hyperlink in the email and executes a shortcut link file (LNK) disguised as a photo (PNG) file contained within the archive.

Persistence

1 technique
T1547.001Registry Run Keys / Startup FolderEvidence1

Checking and setting Run key persistence (HKCU:\Software\Microsoft\Windows\CurrentVersion\Run)

Privilege Escalation

1 technique
T1547.001Registry Run Keys / Startup FolderEvidence1

Checking and setting Run key persistence (HKCU:\Software\Microsoft\Windows\CurrentVersion\Run)

Stealth

2 techniques
T1027Obfuscated Files or InformationEvidence1

This RAT malware employs VM-based obfuscation, making it impossible to reveal details through pure static analysis alone.

T1036MasqueradingEvidence1

the infection began when the user clicked a shortcut link file (LNK) disguised as a photo file within the zip archive.

Credential Access

2 techniques
T1003OS Credential DumpingEvidence1

The deployed executable was observed performing operations on the following folders and involving the “C:\Windows\System32\lsass.exe” process.

T1555Credentials from Password StoresEvidence1

These folders contain browser-stored password SQLite DBs, Cookie DBs, History, autofill, bookmark information, and other data, raising suspicion of exfiltration by the attacker.

Discovery

3 techniques
T1033System Owner/User DiscoveryEvidence1

The endpoint information transmission in type:4 was confirmed to contain the following information... the endpoint's username, hostname

T1082System Information DiscoveryEvidence1

The endpoint information transmission in type:4 was confirmed to contain the following information... the endpoint's username, hostname, as well as OS, CPU core count, memory information, and MAC address hardware information.

T1083File and Directory DiscoveryEvidence1

The deployed executable was observed performing operations on the following folders... C:\Users\<UserName>\AppData\Local\Google\Chrome\User Data\ C:\Users\<UserName>\AppData\Local\Microsoft\Edge\User Data\

Command and Control

4 techniques
T1071.001Web ProtocolsEvidence1

Connection to C&C domain via WebSocket communication | At this point, the server verifies whether the User-Agent contains the string "Powershell." If "Powershell" is not present ... if "Powershell" is present, a 200 OK response returns the PS1 file script string.

T1102.001Dead Drop ResolverEvidence1

the malware abuses The Open Network (TON) blockchain platform as a dead drop resolver, a technique that allows attackers to update their command-and-control (C&C) server destination without hardcoding it into the malware

T1105Ingress Tool TransferEvidence1

If Node.exe does not exist, “node-v24.13.0-win-x64.zip” is retrieved from the official Node.js website (nodejs.org) and extracted under "%USERPROFILE%\AppData\Local\Nodejs."

T1219Remote Access ToolsEvidence1

The JavaScript file executed with arguments by node.exe (detection name: TrojanSpy.JS.TONRESOLVER.A) was identified as malware functioning as a remote access trojan (RAT).

Exfiltration

1 technique
T1029Scheduled TransferEvidence1

Keepalive every 20 seconds

INDICATORS OF COMPROMISE

IOCs tracked for this family

15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
11 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
hash.sha256●●●●●●●●●●●●View more in apptoday
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching15

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping19

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.