Find notable cyber news and cases, enriched with sources, timelines, and signals.

TA558 RevengeHotels phishing campaign targeting hotels in Brazil and Spanish-speaking markets

Campaign
First reported
Last updated
Happening score
H score 51
1 unique sources, 1 articles

Summary

Hide ▲

The TA558 / RevengeHotels operation expanded a summer 2025 phishing run against hotels in Brazil and Spanish-speaking markets, using invoice, reservation, and job application lures to deliver Venom RAT. The infection chain relied on JavaScript and PowerShell loaders, with some code reportedly shaped by LLM agents. The campaign matters because it targets hospitality systems that hold guest credit card data and has evolved through repeated payload swaps and lure refinements.

Related Happenings

Vercel v0.dev phishing campaign using GenAI-built lure pages

Campaign
First: 07.05.2026 11:30 Last: 07.05.2026 11:30 Sources 1

About this happening: A campaign using **Vercel v0.dev** to build **highly convincing phishing pages** has lowered the skill and cost needed to run fraudulent sign-in and job-lure attacks. The activity...

Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT

Campaign
First: 04.05.2026 14:57 Last: 04.05.2026 14:57 Sources 1

About this happening: **Silver Fox** is running a **tax-themed phishing campaign** that now targets **India** with **Income Tax Department** lures and delivers **ValleyRAT (aka Winos 4.0)**. The campai...

FBI-led takedown of W3LL phishing network

Law Enforcement
First: 13.04.2026 13:35 Last: 13.04.2026 13:35 Sources 1

About this happening: **FBI Atlanta** and **US and Indonesian law enforcement** took down the **W3LL** phishing network, escalating a cross-border cybercrime case tied to **more than $20 million in fra...

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: **Storm-1175** is running a **high-tempo Medusa ransomware campaign** that has repeatedly exploited **n-day and zero-day flaws** to gain initial access before patching closes the...

OAuth device-code phishing campaign targeting SaaS accounts

Campaign
First: 04.04.2026 17:17 Last: 04.04.2026 17:17 Sources 1

About this happening: A **device code phishing** campaign now includes **EvilTokens**, a **phishing-as-a-service** kit sold on **Telegram** that uses the **OAuth 2.0 device authorization flow** to hija...

Timeline

  1. 17.09.2025 21:30 2 articles · 8mo ago

    TA558 RevengeHotels phishing campaign targeting hotels in Brazil and Spanish-speaking markets

    Initial Disclosure

    The opening phase used **Portuguese- and Spanish-language phishing emails** with **hotel reservation** and **job application** lures to steer victims to a malicious link. That click started a **WScript/PowerShell** infection chain that prepared the host for **Venom RAT** delivery.

    Show sources