Threat Advisory

Cybercrime Group TA558 Targeting Hospitality, Hotel, and Travel Organizations

Threat: APT
Criticality: High
[subscribe_to_unlock_form]

Summary:

A financially motivated cybercrime group TA558 has been linked to an ongoing wave of attacks aimed at hospitality, hotel, and travel organizations in Latin America with the goal of installing malware on compromised systems. Since 2018, this group has used consistent tactics, techniques, and procedures to attempt to install a variety of malware including Vjw0rm, and Revenge RAT. The group has been operational at a higher tempo in 2022 than usual, with intrusions mainly geared towards Portuguese and Spanish speakers in Latin America, and to a lesser extent in Western Europe and North America.[/subscribe_to_unlock_form]

Summary:

A financially motivated cybercrime group TA558 has been linked to an ongoing wave of attacks aimed at hospitality, hotel, and travel organizations in Latin America with the goal of installing malware on compromised systems. Since 2018, this group has used consistent tactics, techniques, and procedures to attempt to install a variety of malware including Vjw0rm, and Revenge RAT. The group has been operational at a higher tempo in 2022 than usual, with intrusions mainly geared towards Portuguese and Spanish speakers in Latin America, and to a lesser extent in Western Europe and North America.[emaillocker id="1283"]

Phishing campaigns mounted by the group involve sending malicious spam messages with reservation-themed lures such as hotel bookings that contain weaponized documents or URLs in a bid to entice unwitting users into installing trojans capable of reconnaissance, data theft, and distribution of follow-on payloads. The malware used by TA558 can steal data including hotel customer user and credit card data, allow lateral movement, and deliver follow-on payloads, Activity conducted by this actor could lead to data theft of both corporate and customer data, as well as potential financial losses.

References:

The following reports contain further technical details:

https://thehackernews.com/2022/08/cybercrime-group-ta558-targeting.html

https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel

[/emaillocker]
crossmenu