A sprawling phishing campaign targeting hotels in Japan and Europe used deceptive photo ZIP files and legitimate web services to establish persistent access, while researchers uncovered thousands of potentially connected infrastructure artifacts and victim IP addresses.