TA558 is a financially motivated cybercriminal threat actor active since at least 2018. Activity associated with the group is also tracked as RevengeHotels, while SteganoAmor names its steganography-based campaign. Historically focused on hospitality, hotels, tourism, and travel organizations in Latin America, TA558 primarily targets Portuguese- and Spanish-speaking organizations and also conducts campaigns in English and other languages. Its operations extend to North America, Western Europe, and other regions, with targeting expanding to manufacturing, financial services, government, energy, transportation, information technology, and pharmaceutical organizations. TA558 obtains initial access through phishing emails using reservation requests, booking confirmations, invoices, payment notices, and other business-related lures. It impersonates legitimate companies and abuses compromised SMTP servers to distribute malicious attachments and links. Delivery methods include malicious Office documents, VBA macros, remote template injection, exploitation of vulnerabilities such as CVE-2017-11882 and CVE-2017-0199, and compressed archives or disk images containing scripts. Multistage infection chains frequently combine VBScript, JavaScript, PowerShell, encoded .NET loaders, and payloads concealed within images or text files. Legitimate image-hosting, file-sharing, and text-sharing services provide staging infrastructure, while obfuscation, environment checks, and process injection hinder analysis and detection. The group deploys commodity information stealers and remote-access malware, including Agent Tesla, Remcos, LokiBot, FormBook, Snake Keylogger, XWorm, AsyncRAT, LodaRAT, RevengeRAT, njRAT, and VenomRAT, with GuLoader used in some delivery chains. These operations support credential and browser-session theft, keylogging, reconnaissance, data exfiltration, persistent remote access, and follow-on payload execution. Stolen information is transmitted through channels including FTP and SMTP, sometimes using compromised legitimate infrastructure. Persistence mechanisms include scheduled tasks and startup registry entries. TA558 adapts its delivery methods and malware selection over time, including increased use of archive and disk-image delivery in 2022 and a shift toward Remcos and XWorm as VenomRAT distribution declined in late 2025.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Xmass.vbs эксплуатирует уязвимость редактора уравнений в пакете Microsoft Office, известную как CVE-2017-11882 ... при открытии специально созданного документа происходит переполнение буфера, что позволяет злоумышленникам выполнить произвольный код в системе жертвы.
EML delivers a malicious XLS file; the XLS exploits CVE-2017-0199 to download an HTA script, which then downloads a steganographic image, decrypts and memory-executes a loader, and the loader ultimately executes the AgentTesla family for email-based C2 communication.
In 2021, this actor continued to leverage emails with Office documents containing macros or Office exploits (e.g. CVE-2017-8570) to download and install malware.
259 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated cybercriminal group conducting global phishing-led malware campaigns, heavily targeting Latin America and using steganography to conceal payloads in images hosted on legitimate services before deploying RATs and stealers.
Phishing-led intrusions delivering RATs (e.g., Venom RAT) targeting hotels in Brazil and Spanish-speaking markets; uses AI-generated scripts.
TA558 is described as a cybercriminal group active since 2018, conducting multistage phishing campaigns to steal data and obtain access to organizations' internal systems. F6 attributed 1,022 malicious emails sent between January 1 and May 25, 2024, against manufacturing enterprises, government institutions, and banks in Russia and Belarus to the group. The campaigns predominantly delivered Agent Tesla and Remcos through malicious Office documents, exploitation of CVE-2017-11882, obfuscated scripts, and payloads concealed in images. The article also identifies financial institutions and tourism companies as established targets and notes expansion beyond the group's initial focus on Latin America.
Named as a threat actor that has used Snake Keylogger in campaigns involving steganography and multiple malware families/loaders.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.