TA558, a financially motivated threat actor active since 2018, has persistently targeted hospitality, hotel, and travel organizations—primarily in Latin America—using Portuguese- and Spanish-language reservation and booking lures. Researchers linked the actor to repeated campaign markers such as the string "CDT", fake travel and hotel branding, and attacker-controlled or compromised hospitality infrastructure. Proofpoint reported that TA558 expanded activity and shifted delivery techniques from macro-enabled Office files to URLs and container attachments such as RAR and ISO, while continuing to distribute a broad set of remote access trojans including Loda RAT, Revenge RAT, AsyncRAT, njRAT, Ozone RAT, and Vjw0rm.
Multiple investigations show the campaigns using multi-stage infection chains to gain remote access and steal data. Cisco Talos documented Loda RAT delivery through phishing documents exploiting CVE-2017-11882, with capabilities including keylogging, screenshots, audio capture, FileZilla credential theft, and WMI-based antivirus enumeration. Uptycs tied a Brazilian hotel-themed lure, "Rooming List Reservas para 3 Familias.docx," to Revenge RAT delivered via remote template injection and staged PowerShell and VBScript, while Elastic observed a related booking-themed chain using a fake "Card & Booking Details.docx" document to deploy XWORM and Agent Tesla, disable defenses, create persistence, and exfiltrate data through a Discord webhook. The activity indicates sustained credential theft, reconnaissance, follow-on malware delivery, and potential financial fraud against both travel-sector organizations and their customers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
ThreatBook reported that TA558 began heavily using image-based steganographic payload hosting in early December 2025, hiding malicious code in image files hosted on services such as archive.org, Cloudinary, Google Drive, and IPFS-linked infrastructure. The campaign continued through April 2026, used more than 1,400 malicious image-storage URLs, and delivered malware including AgentTesla and XWorm through phishing lures and compressed archives.
In 2022, TA558 used a Spanish-language lure impersonating 155 Hotel in which a URL led to an ISO file and batch file that ultimately installed AsyncRAT.
In 2022, TA558 significantly increased campaign tempo and shifted away from macro-enabled Office documents toward URLs, RAR attachments, and ISO attachments, likely responding to Microsoft's macro-blocking changes.
In 2021, TA558 used more elaborate chains including MSG files and helper scripts; one campaign masqueraded as Unimed and installed AsyncRAT while creating a persistence task named "Spotfy."
The domain azulviagens[.]online, used to impersonate the Brazilian travel brand Azul Viagens in a Revenge RAT campaign, was reportedly registered by the attackers.
In 2020, TA558 stopped using Equation Editor exploits and moved to malicious Office documents with VBA macros, including PowerPoint template-injection chains that installed Revenge RAT.
Proofpoint observed TA558 begin using English-language room-booking lures in addition to Portuguese and Spanish themes.
Cisco Talos reported C2 communications for a Loda RAT campaign dating back to the last quarter of 2019, indicating active operations targeting South America, Central America, and the United States.
In 2019, TA558 continued using CVE-2017-11882 documents, added macro-laden PowerPoint attachments and Office template injection, and expanded some targeting beyond hospitality and tourism to business services and manufacturing.
Proofpoint began tracking TA558 as a likely financially motivated cybercrime threat actor targeting hospitality, hotel, travel, and related organizations, primarily in Latin America.
In 2018, TA558 used malicious Word attachments exploiting CVE-2017-11882 and remote template URLs to deliver malware including Revenge RAT in reservation-themed phishing campaigns.
Elastic Security Labs described a campaign using the fake document "Card & Booking Details.docx" to fetch a malicious RTF from MediaFire, execute PowerShell, establish persistence, and deploy XWORM and Agent Tesla.
Uptycs analyzed a multi-stage campaign active in Brazil that used a reservation-themed Word document, dynamic Office template injection, embedded XLSM files, and PowerShell/VBScript stages to install Revenge RAT.
Cisco Talos observed a phishing campaign delivering Loda RAT 1.1.1 through a DOCX-to-RTF infection chain exploiting CVE-2017-11882 to install a malicious MSI payload.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
threatbook.io
Open sourceelastic.co
Open sourceproofpoint.com
Open sourceuptycs.com
Open sourceblog.talosintelligence.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.