Skip to main content
Mallory
4 malware families

TA558

Also known asTA558

TA558 is a financially motivated cybercrime threat actor first observed in 2018. It is also tracked as RevengeHotels. The group initially targeted travel, hospitality, and tourism organizations in Latin America, using socially engineered reservation-themed phishing emails, often in Portuguese or Spanish and frequently using "reserva" lures. Reporting also describes TA558 as highly active in Colombia. Over time, the group expanded beyond hospitality to target global oil and gas, maritime, industrial, public sector, and electric power organizations, including critical infrastructure in countries such as Brazil, Mexico, Iran, Russia, and Turkey. TA558 is known for phishing-driven delivery of commodity malware and RATs including Agent Tesla, Remcos RAT, LokiBot, FormBook, GuLoader, Snake Keylogger, XWorm, VenomRAT, AsyncRAT, Loda, and Revenge RAT. Its campaigns have used malicious Excel, RTF, ZIP, ISO, and RAR container files, as well as image or text attachments containing steganographically embedded VBS, PowerShell, or RTF payloads. The group’s "SteganoAmor" campaign used steganography to embed malicious payloads in images and text files. TA558 has also exploited Microsoft Office techniques including CVE-2017-11882 and template injection, and later shifted toward URL-based delivery of ISO and RAR payloads, likely in response to Microsoft disabling Office macros by default. Observed infection chains include phishing emails linking to container files with executables, embedded BAT files, and PowerShell downloaders. TA558 commonly uses obfuscated VBScript and PowerShell, high-entropy files, and living-off-the-land techniques. The group has leveraged legitimate-but-compromised SMTP servers for phishing and compromised FTP/SMTP servers for command-and-control and data exfiltration, as well as legitimate services and infrastructure to evade detection. Reporting also notes use of free image-uploading and text-sharing sites for payload retrieval. TA558’s operations are assessed as primarily financially motivated, with objectives including credential theft, data exfiltration, and enabling fraud or extortion. Multiple vendors have tracked the actor from 2018 through at least May 2024, and one report notes TA558 as a key distributor of VenomRAT targeting Portuguese and Spanish speakers in Latin America before shifting to other malware. The group has been linked in reporting to shared tactics or infrastructure with Aggah and Blind Eagle, including shared use of the Crypters AndTools packing service, but the content does not state these are aliases or sub-groups.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • travel
  • hospitality
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

TA558 | Mallory