TA558 is a financially motivated cybercrime threat actor tracked since at least 2018. It is also referred to as RevengeHotels in some reporting. The group has primarily targeted Portuguese- and Spanish-speaking victims, especially in Latin America, with additional targeting observed in Western Europe and North America. Early and sustained targeting has focused on travel and hospitality organizations, using reservation-themed phishing lures, and later expanded to broader sectors including oil and gas, maritime, industrial, public sector, and electric power. TA558 is known for phishing-driven delivery of commodity malware and RATs, including VenomRAT, Remcos RAT, XWorm, njRAT, PDQ Connect, Agent Tesla, LokiBot, FormBook, GuLoader, Snake Keylogger, Loda, Revenge RAT, and AsyncRAT. Proofpoint identified TA558 as the most prominent distributor of VenomRAT in its email campaign data, accounting for 58% of observed VenomRAT activity since 2022. Reporting indicates TA558 shifted away from VenomRAT by September 2025 and began favoring other malware such as Remcos RAT and XWorm. Its campaigns commonly use spearphishing or malspam emails in Portuguese, Spanish, and occasionally English. Observed delivery chains include URLs leading to JavaScript files that spawn PowerShell to download malware; links to ISO, RAR, or ZIP container files containing executables; and attachments such as malicious Excel, RTF, image, or text files. TA558 has used BAT-to-PowerShell chains, obfuscated VBScript and PowerShell, and historically exploited Microsoft Office techniques including CVE-2017-11882 and template injection. Multiple reports describe TA558 campaigns using steganography to embed VBS, PowerShell, or RTF payloads in images or text files, including the SteganoAmor campaign. The actor has also used legitimate or compromised infrastructure to evade detection, including compromised SMTP and FTP servers, free image-uploading and text-sharing sites, paste.ee, Google Drive, and ngrok-tunneled RAT operations. Reported objectives are credential theft, data exfiltration, and fraud or extortion. Some reporting notes overlaps in tactics or infrastructure with Aggah and Blind Eagle, but the content does not establish them as aliases or sub-groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-led intrusions delivering RATs (e.g., Venom RAT) targeting hotels in Brazil and Spanish-speaking markets; uses AI-generated scripts.
Named as a threat actor that has used Snake Keylogger in campaigns involving steganography and multiple malware families/loaders.
TA558 is known for distributing VenomRAT, primarily targeting Portuguese and Spanish speakers, typically located in Latin America. They have shifted to other malware as of September 2025.
TA558 is known for distributing VenomRAT, primarily targeting Portuguese and Spanish speakers, typically located in Latin America. They have shifted to other malware as of September 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.