A sophisticated cybercriminal group known as TA558, tracked by security researchers as RevengeHotels, has launched a new wave of attacks targeting hotels across Brazil and Spanish-speaking markets. The campaign, identified by Kaspersky in summer 2025, represents a concerning evolution in cybercrime tactics through the integration of artificial intelligence.
## AI-Powered Attack Strategy
The threat actors are employing large language models (LLMs) to generate malicious code, marking a significant shift in cybercriminal operations. These AI-enhanced attacks use phishing emails disguised as hotel invoices to deliver Venom RAT malware through JavaScript loaders and PowerShell downloaders.
“A significant portion of the initial infector and downloader code appears to be generated by large language model agents,” Kaspersky researchers noted, highlighting how criminals are leveraging AI to improve their attack methods.
## Campaign Evolution
RevengeHotels has been active since 2015, consistently targeting hospitality, hotel, and travel organizations throughout Latin America. The group’s tactics have evolved considerably:
**Early campaigns** used malicious Word, Excel, and PDF documents exploiting Microsoft Office vulnerabilities (CVE-2017-0199) to deploy various remote access trojans including Revenge RAT, NjRAT, and custom malware called ProCC.
**Recent operations** have expanded to deliver a broader range of malware including Agent Tesla, AsyncRAT, FormBook, and Snake Keylogger, demonstrating the group’s adaptability and technical sophistication.
## Current Attack Method
The latest campaign follows a multi-stage infection process:
1. **Initial Contact**: Phishing emails in Portuguese and Spanish use hotel reservation and job application themes
2. **Payload Delivery**: Victims click fraudulent links, downloading WScript JavaScript files with AI-generated, heavily commented code
3. **Multi-Stage Loading**: PowerShell scripts retrieve additional payloads from external servers
4. **Final Deployment**: Venom RAT malware is installed on compromised systems
## Venom RAT Capabilities
The attackers deploy Venom RAT, a commercial tool based on the open-source Quasar RAT, available for $650 lifetime license or $350 monthly subscription. This sophisticated malware features:
– **Data theft capabilities** for stealing sensitive information
– **Anti-kill protection** that prevents security tools from terminating the malware
– **Persistence mechanisms** using Windows Registry modifications
– **System manipulation** including disabling sleep mode and maintaining display activity
– **Security evasion** by terminating Microsoft Defender processes and disabling security features
## Primary Objectives
The campaign’s main goal is stealing credit card data from hotel guests and information received from online travel agencies like Booking.com. This financial motivation drives the group’s continued focus on the hospitality sector.
## Industry Impact
This development represents a troubling trend where cybercriminals are incorporating AI tools to enhance their operations, making attacks more sophisticated and harder to detect. The hospitality industry, already vulnerable due to the sensitive customer data it handles, faces increased risks from these AI-enhanced threats.
Security experts recommend that hotels and travel organizations strengthen their email security, implement robust endpoint protection, and provide comprehensive cybersecurity training to staff to defend against these evolving threats.
