TA558 is a financially motivated cybercrime threat actor active since at least 2018 and widely associated with the SteganoAmor campaign; some reporting also tracks overlapping activity as RevengeHotels. The actor initially focused on hospitality, hotel, travel, and tourism organizations, especially Portuguese- and Spanish-speaking targets in Latin America, and later expanded to additional sectors including government, finance, energy, transportation, information technology, education, pharmaceuticals, maritime, and industrial organizations. Activity has also been observed beyond Latin America, including North America, Western Europe, Russia, the Middle East, and Japan. TA558 primarily gains initial access through phishing and malspam campaigns using reservation, booking, invoice, shipping, tax, and payment-themed lures. Campaigns are commonly written in Portuguese and Spanish, with English also used for broader targeting. Delivery methods have evolved over time from malicious Office documents exploiting vulnerabilities such as CVE-2017-11882, CVE-2017-8570, and CVE-2017-0199, to template injection, macro-enabled documents, URLs, compressed archives, and container files such as ISO and RAR. The actor has repeatedly adapted delivery techniques in response to defensive changes, including reduced reliance on Office macros. A defining characteristic of TA558 is the use of steganography and legitimate web services to stage payloads. Campaigns have hidden malicious code or loaders inside image files and retrieved follow-on content from public hosting, file-sharing, and text-sharing platforms. The actor has also used compromised SMTP and FTP infrastructure and other legitimate services to improve phishing credibility, blend malicious traffic with normal activity, and support payload retrieval or exfiltration. TA558 deploys a broad set of commodity malware, especially remote access trojans and information stealers. Reported payloads include AgentTesla, AsyncRAT, LodaRAT, Revenge RAT, VenomRAT, XWorm, Remcos, LokiBot, FormBook, GuLoader, Snake Keylogger, njRAT, Ozone RAT, and Vjw0rm. These payloads support credential theft, keylogging, reconnaissance, remote control, follow-on payload delivery, persistence, and data exfiltration. Observed infection chains have included obfuscated VBScript, JavaScript, PowerShell, HTA, VBE, VBA, and BAT stages; persistence via scheduled tasks, startup items, and Run-key style autoruns; and process injection or process hollowing into legitimate Windows binaries. TA558 is best understood as an eCrime actor focused on credential theft, information theft, and monetizable access rather than espionage. Its long-running emphasis on hospitality and travel, multilingual phishing, commodity malware delivery, and steganography-based staging make it a distinctive and persistent threat cluster in the cybercrime ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
EML delivers a malicious XLS file; the XLS exploits CVE-2017-0199 to download an HTA script, which then downloads a steganographic image, decrypts and memory-executes a loader, and the loader ultimately executes the AgentTesla family for email-based C2 communication.
These early campaigns typically used malicious Word attachments that exploited Equation Editor vulnerabilities (e.g. CVE-2017-11882) or remote template URLs to download and install malware.
In 2021, this actor continued to leverage emails with Office documents containing macros or Office exploits (e.g. CVE-2017-8570) to download and install malware.
108 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated cybercriminal group conducting global phishing-led malware campaigns, heavily targeting Latin America and using steganography to conceal payloads in images hosted on legitimate services before deploying RATs and stealers.
Phishing-led intrusions delivering RATs (e.g., Venom RAT) targeting hotels in Brazil and Spanish-speaking markets; uses AI-generated scripts.
Named as a threat actor that has used Snake Keylogger in campaigns involving steganography and multiple malware families/loaders.
TA558 is known for distributing VenomRAT, primarily targeting Portuguese and Spanish speakers, typically located in Latin America. They have shifted to other malware as of September 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.