Hotels in Latin America were targeted with fake booking-request emails carrying malicious OpenDocument Text (.odt) attachments that delivered AsyncRAT through a multi-stage infection chain. HP Wolf Security reported that the .odt files used external OLE references to retrieve a remote Word document with embedded Excel files, which then prompted victims to enable macros. Researchers said the lures appeared in Spanish and Portuguese and found signs that similar activity had been running for months.
The attack relied on mshta.exe to proxy execution and evade suspicion, using VBA macros to launch a sequence involving PowerShell, VBScript, and batch scripts before creating a scheduled task for persistence. The use of mshta.exe aligns with the MITRE ATT&CK technique T1218.005, which documents abuse of the legitimate Microsoft HTML Application Host as a living-off-the-land binary for stealthy code execution and payload staging. HP said the malicious .odt files showed exceptionally low antivirus detection, including a reported 0% detection rate on VirusTotal at the time of analysis.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
As of 7 July 2022, HP Wolf Security reported that the malicious ODT document used in the campaign had a 0% detection rate on VirusTotal. The low detection rate distinguished it from a similar Word-based lure seen later.
In July 2022, researchers observed another malicious document campaign using the same lure image and impersonating a legitimate organization, but delivered through Microsoft Word documents instead of OpenDocument files. This Word-based lure had a much higher detection rate than the ODT-based lure.
In late June 2022, HP Wolf Security isolated a malware campaign that used fake booking-request emails and malicious OpenDocument Text files to target hotels in Latin America. The infection chain ultimately delivered AsyncRAT and used external OLE references plus macro-enabled embedded Excel content.
HP Wolf Security found evidence that related activity targeting Latin American hotels with Portuguese- and Spanish-language lures had been ongoing for several months before the late-June 2022 campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.