RevengeHotels is a financially motivated cybercrime cluster focused on the hospitality and travel sector, active since at least 2015. The group is known for phishing-led intrusions against hotels and related organizations, with the objective of stealing payment-card and guest data from front-desk systems and online travel workflows. Reporting has linked recent activity to TA558 and tracked it as part of the RevengeHotels cluster. The actor has targeted hotels and travel organizations in Latin America and other regions, including Brazil and multiple Spanish-speaking markets, and has also been reported targeting victims in parts of Europe and Eurasia. Its campaigns commonly use reservation, invoice, and job-application lures in Portuguese and Spanish to induce victims to open malicious attachments or download staged payloads. Across campaigns, RevengeHotels has delivered a broad set of commodity and custom malware, including Venom RAT, Revenge RAT, njRAT, NanoCoreRAT, 888 RAT, Agent Tesla, AsyncRAT, FormBook, GuLoader, Loda RAT, LokiBot, Remcos RAT, Snake Keylogger, Vjw0rm, and custom malware referred to as ProCC. Earlier operations used malicious Office and PDF attachments, including exploitation of CVE-2017-0199. More recent activity has used multi-stage script-based infection chains and large language model-assisted generation of initial infector and downloader code. Observed capabilities include credential and payment-data theft, keylogging, persistence through Windows Registry changes and startup mechanisms, exfiltration, and post-exploitation via remote access trojans. In recent Venom RAT-based operations, the malware has shown defense-evasion behavior including termination of security tools, tampering with security-related settings, anti-kill protections, and abuse of elevated privileges. Additional reported functionality includes reverse-proxy behavior and propagation via removable media. RevengeHotels is best characterized as a long-running hospitality-focused cybercrime operation rather than a nation-state actor. Its tradecraft centers on scalable phishing, commodity malware delivery, and theft of monetizable victim data, especially payment-card information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Группа, специализирующаяся на краже данных кредитных карт у туристов; в описанных тактиках отмечены признаки использования LLM-сгенерированного кода для начального заражения и загрузки имплантов.
RevengeHotels is a cybercriminal group specializing in targeting hotels and tourism firms, primarily in Brazil and Latin America, to steal payment card data and guest information. The group uses phishing emails and AI-generated malware to compromise hotel systems.
RevengeHotels is a cybercriminal group specializing in targeting hotels and tourism firms, primarily in Brazil and Latin America, to steal payment card data and guest information. The group uses phishing emails and AI-generated malware to compromise hotel systems.
RevengeHotels is conducting phishing campaigns targeting hospitality, hotel, and travel organizations in Latin America and Spanish-speaking markets, aiming to install RATs and steal credit card data from hotel systems and online travel agencies. The group has recently adopted AI-generated scripts and enhanced anti-analysis and persistence techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.