Brazilian Hotels Under Siege: Cybercriminals Weaponize AI to Launch Sophisticated Venom RAT Attacks

# TA558 Cybercriminals Target Hotels with AI-Enhanced Attacks

A sophisticated cybercriminal group known as TA558, tracked by security researchers as RevengeHotels, has launched a new wave of attacks targeting hotels across Brazil and Spanish-speaking markets. The campaign, identified by Kaspersky in summer 2025, represents a concerning evolution in cybercrime tactics through the integration of artificial intelligence.

## AI-Powered Attack Strategy

The threat actors are employing large language models (LLMs) to generate malicious code, marking a significant shift in cybercriminal operations. These AI-enhanced attacks use phishing emails disguised as hotel invoices to deliver Venom RAT malware through JavaScript loaders and PowerShell downloaders.

“A significant portion of the initial infector and downloader code appears to be generated by large language model agents,” Kaspersky researchers noted, highlighting how criminals are leveraging AI to improve their attack methods.

## Campaign Evolution

RevengeHotels has been active since 2015, consistently targeting hospitality, hotel, and travel organizations throughout Latin America. The group’s tactics have evolved considerably:

**Early campaigns** used malicious Word, Excel, and PDF documents exploiting Microsoft Office vulnerabilities (CVE-2017-0199) to deploy various remote access trojans including Revenge RAT, NjRAT, and custom malware called ProCC.

**Recent operations** have expanded to deliver a broader range of malware including Agent Tesla, AsyncRAT, FormBook, and Snake Keylogger, demonstrating the group’s adaptability and technical sophistication.

## Current Attack Method

The latest campaign follows a multi-stage infection process:

1. **Initial Contact**: Phishing emails in Portuguese and Spanish use hotel reservation and job application themes
2. **Payload Delivery**: Victims click fraudulent links, downloading WScript JavaScript files with AI-generated, heavily commented code
3. **Multi-Stage Loading**: PowerShell scripts retrieve additional payloads from external servers
4. **Final Deployment**: Venom RAT malware is installed on compromised systems

## Venom RAT Capabilities

The attackers deploy Venom RAT, a commercial tool based on the open-source Quasar RAT, available for $650 lifetime license or $350 monthly subscription. This sophisticated malware features:

– **Data theft capabilities** for stealing sensitive information
– **Anti-kill protection** that prevents security tools from terminating the malware
– **Persistence mechanisms** using Windows Registry modifications
– **System manipulation** including disabling sleep mode and maintaining display activity
– **Security evasion** by terminating Microsoft Defender processes and disabling security features

## Primary Objectives

The campaign’s main goal is stealing credit card data from hotel guests and information received from online travel agencies like Booking.com. This financial motivation drives the group’s continued focus on the hospitality sector.

## Industry Impact

This development represents a troubling trend where cybercriminals are incorporating AI tools to enhance their operations, making attacks more sophisticated and harder to detect. The hospitality industry, already vulnerable due to the sensitive customer data it handles, faces increased risks from these AI-enhanced threats.

Security experts recommend that hotels and travel organizations strengthen their email security, implement robust endpoint protection, and provide comprehensive cybersecurity training to staff to defend against these evolving threats.

Share This Article