RevengeHotels Leverages AI-Generated Code to Deliver VenomRAT Malware through Phishing Emails
RevengeHotels, a threat group active since 2015, has been stealing credit card data from hotel guests and travelers. The group has recently been using AI-generated code to deliver VenomRAT malware through phishing emails targeting hotel staff. The incorporation of AI into the VenomRAT malware makes RevengeHotels increasingly dangerous, as it accelerates exploit discovery and proof-of-concept development, automates the creation of polymorphic malware and obfuscated payloads that evade signature-based defenses.
Key Takeaways:
- RevengeHotels, also known as TA558, has been active since 2015, stealing credit card data from hotel guests and travelers.
- The group is now using AI-generated code to deliver VenomRAT malware through phishing emails targeting hotel staff.
- The incorporation of AI into the VenomRAT malware makes RevengeHotels increasingly dangerous, as it accelerates exploit discovery and proof-of-concept development.
- AI automates the creation of polymorphic malware and obfuscated payloads that evade signature-based defenses.
- The threat actor uses phishing emails disguised as requests for reservation, urging recipients to review the attached documents.
- Mayank Kumar, Founding AI Engineer at DeepTempo, explains that the threat landscape has shifted from slow, expert-driven campaigns to fast, scalable, and more evasive operations.
- Kumar finds that the blend of LLMs and VenomRAT has created sophisticated credential theft and data exfiltration operations built with production-grade precision.
- Spanish-language lures from RevengeHotels are already hitting targets across Latin America and Europe, proving how easily AI erases language and cultural friction.
- Kumar is concerned that this is giving way to an even wider shift of state-backed groups using GenAI for malware refinement, disinformation, and deepfake ID phishing.
- Defenders must stop relying on static signatures and upgrade to behavior-based anomaly detection to catch AI-spawned attacks like those of RevengeHotels.
Statistics:
- Since 2015, RevengeHotels has been stealing credit card data from hotel guests and travelers.
- The group has now incorporated AI-generated code to deliver VenomRAT malware through phishing emails targeting hotel staff.
- AI accelerates exploit discovery and proof-of-concept development, automating the creation of polymorphic malware and obfuscated payloads that evade signature-based defenses.
- The threat actor uses phishing emails disguised as requests for reservation, with approximately 50% of targets being hit successfully.
Sources:
- Security Online: "RevengeHotels Strikes Back: AI-Generated Phishing and a New Rat Targeting Hotels"
- Digital Journal: "RevengeHotels: AI Weakens Cybersecurity for Holidaymakers"