Executive Summary
In the summer of 2025, the threat actor group TA558 launched a series of targeted phishing campaigns against hotels and the hospitality sector in Brazil and other Spanish-speaking regions. Leveraging AI-generated scripts, TA558 distributed Remote Access Trojans (RAT) such as Venom RAT via malicious email attachments disguised as business invoices. The attackers gained unauthorized access to hotel infrastructure, enabling surveillance, data theft, and lateral movement within targeted environments. Kaspersky researchers attributed the activity to the RevengeHotels cluster and noted reliance on sophisticated social engineering and automation.
This incident exemplifies the rising integration of AI in cyberattacks, increasing the efficacy and resilience of threat actors like TA558. Organizations in hospitality and other sectors with valuable customer data face growing risks from AI-driven malware and must adapt their defenses to faster-evolving adversarial techniques.
Why This Matters Now
AI-powered phishing and malware, as seen in the TA558 campaign, amplify both speed and stealth of attacks, making traditional security controls less effective. With the hospitality sector increasingly digitized and targeted, urgent improvements in behavioral detection, lateral traffic security, and zero trust segmentation are needed to mitigate data breach risk.
Attack Path Analysis
TA558 initiated the attack by delivering AI-generated malicious scripts via phishing emails, leading to the deployment of Venom RAT on hotel systems. Post-compromise, the malware likely sought to escalate privileges to gain broader access within targeted networks. Using the RAT, the attackers moved laterally, probing for additional reachable systems and sensitive data. Once internal footholds were secured, the RAT established command and control channels to external infrastructure for tasking and persistence. Sensitive data was exfiltrated through covert outbound connections, potentially leveraging encrypted channels or protocol abuse. The ultimate impact included surveillance, credential theft, and possible financial or reputational damage to the hotel victims.
Kill Chain Progression
Initial Compromise
Description
TA558 delivered phishing emails with AI-generated scripts, resulting in the execution of Venom RAT on victim endpoints.
Related CVEs
CVE-2017-0199
CVSS 7.8A remote code execution vulnerability in Microsoft Office allows attackers to execute arbitrary code via crafted documents.
Affected Products:
Microsoft Office – 2010, 2013, 2016
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Attachment
PowerShell
Malicious File
Ingress Tool Transfer
Obfuscated Files or Information
Registry Run Keys / Startup Folder
Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Phishing and Social Engineering Awareness
Control ID: 5.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Mitigating Phishing Risks
Control ID: Identity Pillar - Phishing Resistant Authentication
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Hospitality
Direct target of TA558's Venom RAT attacks on Brazilian hotels, requiring enhanced egress security and threat detection capabilities against phishing campaigns.
Information Technology/IT
Critical need for zero trust segmentation and anomaly detection systems to prevent lateral movement and remote access trojan infiltration across networks.
Financial Services
High-value target requiring multicloud visibility and encrypted traffic protection against AI-generated scripts and remote access trojans for compliance maintenance.
Health Care / Life Sciences
HIPAA compliance mandates enhanced east-west traffic security and threat detection to protect against sophisticated RAT attacks and data exfiltration risks.
Sources
- TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attackshttps://thehackernews.com/2025/09/ta558-uses-ai-generated-scripts-to.htmlVerified
- Kaspersky discovers the return of RevengeHotels, leveraging AI in attacks on Brazilian hotelshttps://www.kaspersky.com/about/press-releases/kaspersky-discovers-the-return-of-revengehotels-leveraging-ai-in-attacks-on-brazilian-hotelsVerified
- Kaspersky warns travelers: AI-powered attacks are targeting hotel guestshttps://me-en.kaspersky.com/about/press-releases/kaspersky-warns-travelers-ai-powered-attacks-are-targeting-hotel-guestsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive Zero Trust segmentation, inline policy enforcement, and enhanced visibility would have contained malware activity, prevented lateral spread, and disrupted data exfiltration and C2 tactics. CNSF-aligned capabilities such as east-west traffic security, egress filtering, encrypted traffic inspection, and threat detection directly target and disrupt each step in TA558’s kill chain.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious endpoint activity could trigger rapid detection and response.
Control: Zero Trust Segmentation
Mitigation: Access to sensitive assets is constrained by least-privilege policies.
Control: East-West Traffic Security
Mitigation: Internal movement across network and cloud is limited and monitored.
Control: Egress Security & Policy Enforcement
Mitigation: C2 traffic is detected and blocked at outbound enforcement points.
Control: Encrypted Traffic (HPE)
Mitigation: Data leaving the environment can be inspected or blocked based on policy and encryption status.
Abnormal system actions and data flows are surfaced for immediate remediation.
Impact at a Glance
Affected Business Functions
- Reservations
- Guest Services
- Payment Processing
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of guests' credit card information and personal data due to unauthorized access to hotel reservation systems.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation and least-privilege access to limit the blast radius from initial compromise.
- • Deploy advanced east-west traffic controls and egress policy enforcement to prevent RAT-driven lateral movement and external communications.
- • Integrate behavioral threat detection and anomaly response to rapidly identify malware activity and AI-generated script execution.
- • Ensure visibility and inline inspection of encrypted traffic to surface covert data exfiltration attempts.
- • Centralize multicloud monitoring and incident response workflows to accelerate detection and containment of attacker actions.



