TA558 is a financially motivated cybercrime threat actor active since at least 2018 and widely tracked for large-scale phishing campaigns that deliver commodity malware. The group is best known for targeting Portuguese- and Spanish-speaking victims, especially in Latin America, while also conducting campaigns against organizations in Western Europe and North America. TA558 has been associated with sustained targeting of travel and hospitality organizations and later expanded into oil and gas, maritime, industrial, public-sector, and electric power environments, including critical infrastructure. TA558 commonly uses spearphishing and malspam with reservation-themed, legal, or business-relevant lures in Portuguese, Spanish, and occasionally English. Delivery methods have included malicious links, ISO and archive containers, image and text attachments, and Office-based exploit or template-injection chains. The actor has repeatedly used steganography to conceal VBS, PowerShell, RTF, or related payload components inside benign-looking files, a tradecraft cluster often referred to as the SteganoAmor campaign. TA558 has also exploited legacy Office vulnerabilities including CVE-2017-11882 and has adapted delivery methods over time, including shifting toward URL-based container delivery after macro restrictions became more effective. The actor’s malware arsenal is diverse and heavily centered on commodity RATs and stealers, including VenomRAT, Remcos RAT, XWorm, Agent Tesla, LokiBot, FormBook, Snake Keylogger, njRAT, GuLoader, AsyncRAT, Loda, Revenge RAT, and PDQ Connect. TA558 has been identified as the most prominent distributor of VenomRAT in some reporting and later shifted toward other malware families such as Remcos RAT and XWorm. Operations are oriented toward credential theft, remote access, information theft, and follow-on fraud-enabling activity rather than destructive effects. TA558 frequently abuses legitimate or compromised infrastructure for delivery, command-and-control, and exfiltration, including compromised SMTP and FTP services and public file-sharing or text-sharing platforms. Reported tradecraft includes obfuscated script chains, PowerShell-based download-and-execute flows, living-off-the-land techniques, and use of legitimate services to reduce detection. The group has also shown overlap in tactics and infrastructure with other Latin America-focused eCrime activity clusters, and has been tracked under the alias RevengeHotels in some reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-led intrusions delivering RATs (e.g., Venom RAT) targeting hotels in Brazil and Spanish-speaking markets; uses AI-generated scripts.
Named as a threat actor that has used Snake Keylogger in campaigns involving steganography and multiple malware families/loaders.
TA558 is known for distributing VenomRAT, primarily targeting Portuguese and Spanish speakers, typically located in Latin America. They have shifted to other malware as of September 2025.
TA558 is known for distributing VenomRAT, primarily targeting Portuguese and Spanish speakers, typically located in Latin America. They have shifted to other malware as of September 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.