RevengeHotels Deploys AI-Powered Venom RAT in Brazil Hotel Cyberattacks
TA558 threat group uses AI-generated phishing scripts to infect Brazilian hotels with Venom RAT, stealing credit card data and evading detection in 2025 attacks.

Russian cybersecurity firm Kaspersky has exposed new attacks by the TA558 threat actor (tracked as RevengeHotels) targeting hotels in Brazil and Spanish-speaking markets. The campaign, observed in summer 2025, deployed Venom RAT using AI-generated phishing scripts.
Key Findings
- Attack Method: Phishing emails with invoice themes deliver malicious JavaScript loaders and PowerShell downloaders.
- AI Involvement: A significant portion of the initial infector code appears generated by large language models (LLMs).
- Primary Target: Hospitality and travel organizations in Latin America, with stolen credit card data as the main goal.

Attack Chain Breakdown
- Phishing Emails: Sent in Portuguese/Spanish with hotel reservation or job application lures.
- JavaScript Payload: Downloads a script (suspected LLM-generated) to fetch additional malicious components.
- PowerShell Downloader: Retrieves "cargajecerrr.txt" from external servers, which then loads Venom RAT.
Venom RAT Capabilities
- Based on open-source Quasar RAT, sold for $650 (lifetime license) or $350/month (bundled with HVNC/Stealer).
- Anti-Kill Mechanism: Terminates security processes, modifies DACL permissions, and ensures continuous operation.
- Persistence: Uses Registry modifications and marks itself as a critical system process.
- Lateral Movement: Spreads via USB drives and disables Microsoft Defender Antivirus.
Historical Context
RevengeHotels has targeted hotels since 2015, previously distributing malware like:
- Revenge RAT, NjRAT, NanoCoreRAT
Related News
CometJacking Attack Hijacks Perplexity AI Browser to Steal User Data
A malicious URL exploit turns Perplexity's Comet AI browser into a data thief, exfiltrating emails, calendar, and memory via encoded payloads.
Zero Trust Auditing Essential for AI Era Cybersecurity
Exploring how Zero Trust Auditing is redefining enterprise assurance in the AI era by continuously verifying trust across devices, networks, and AI systems.
About the Author

David Chen
AI Startup Analyst
Senior analyst focusing on AI startup ecosystem with 11 years of venture capital and startup analysis experience. Former member of Sequoia Capital AI investment team, now independent analyst writing AI startup and investment analysis articles for Forbes, Harvard Business Review and other publications.