Listen to this Post

Introduction
Cybercrime in the hospitality sector is escalating at an alarming rate. In 2025, a notorious cybercrime group known as TA558, also tracked as RevengeHotels, has been linked to a surge of new attacks against hotels in Brazil and Spanish-speaking countries. What makes these attacks stand out is the use of artificial intelligence (AI) and large language model (LLM) agents to generate malicious scripts, phishing campaigns, and loaders. By blending AI with traditional malware delivery techniques, TA558 has significantly enhanced its ability to compromise hotel systems, steal guest payment data, and bypass security defenses.
The Rise of AI-Enhanced Hotel Attacks
Cybersecurity firm Kaspersky has uncovered that these latest campaigns rely on phishing emails disguised as hotel reservations or job applications. Written in Portuguese and Spanish, the emails contain JavaScript loaders and PowerShell downloaders designed to deliver the Venom RAT malware. The disturbing detail? Much of the code appears AI-generated, with structured comments and formatting resembling LLM-produced scripts.
the Attack Chain
The attack begins with convincing phishing emails, tricking hotel staff into clicking malicious links. Once executed, the emails drop a WScript JavaScript payload, heavily resembling AI output. This script initiates a chain reaction:
A PowerShell downloader retrieves malicious files, including a loader.
The loader deploys Venom RAT, a commercial malware based on Quasar RAT, sold for \$650 lifetime or \$350 monthly with extra components.
Venom RAT infiltrates hotel systems, designed to steal payment data, especially from online travel agencies (OTAs) like Booking.com.
Venom RAT comes with an arsenal of features:
Data theft and reverse proxy functions.
Anti-kill protection by altering permissions (DACL) and killing security-related processes every 50 milliseconds.
Persistence via Windows Registry modifications, ensuring it survives reboots and removal attempts.
Critical system process marking when run with admin rights, making it nearly impossible to terminate.
USB propagation, allowing infections to spread through external devices.
Microsoft Defender termination, disabling default Windows defenses.
These advanced measures highlight just how sophisticated RevengeHotels has become since it first emerged in 2015, evolving from simple malicious attachments to full-blown AI-assisted campaigns.
Expanding Beyond Latin America
Initially, RevengeHotels focused on Latin America, exploiting flaws like CVE-2017-0199 in Microsoft Office. They distributed common malware strains such as Revenge RAT, NjRAT, NanoCoreRAT, and 888 RAT. Over the years, they expanded their toolkit to include Agent Tesla, AsyncRAT, FormBook, LokiBot, Remcos RAT, and Snake Keylogger. Now, by leveraging AI, the group is refining phishing lures and expanding into new regions with enhanced stealth and effectiveness.
What Undercode Say:
The TA558 operations reveal a disturbing evolution in cybercrime, blending traditional phishing with AI-driven enhancements. By incorporating LLM agents, threat actors don’t just automate malicious script generation—they also accelerate attack cycles, test multiple variations of phishing content, and reduce human effort in developing malware delivery chains.
From an analytical perspective:
AI lowers entry barriers for cybercrime: Less-skilled attackers can generate functional scripts without deep coding knowledge.
Phishing efficiency skyrockets: AI-crafted emails appear more authentic, written in native languages, making detection harder.
Anti-kill features mirror APT-level tactics: TA558 now mimics nation-state attack sophistication, using persistence, privilege escalation, and stealthy defenses.
Hotels remain soft targets: With outdated systems and vast amounts of guest payment data, the hospitality industry continues to be a prime cybercrime target.
Commercialization of RATs: Malware like Venom RAT being openly sold with subscription options proves cybercrime has become a professional service industry.
Looking deeper, RevengeHotels exemplifies how AI and cybercrime converge. This shift marks a new era where even mid-tier threat actors gain capabilities once reserved for elite hacking groups.
✅ Fact Checker Results
Kaspersky’s findings confirm TA558’s use of Venom RAT in 2025 campaigns, backed by phishing and AI-generated scripts. RevengeHotels has a documented history since 2015 targeting hotels and tourism industries. The claim is accurate and aligns with past intelligence reports.
🔮 Prediction
With AI-driven cybercrime accelerating, we can expect:
Expansion into Europe and North America, as TA558 adapts its campaigns.
More powerful AI-generated malware loaders, automating infection chains at scale.
Hotels and OTAs facing regulatory crackdowns, as breaches expose sensitive customer data.
Defensive AI tools emerging in response, sparking a new AI vs. AI cyberwarfare era.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: thehackernews.com
Extra Source Hub:
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




