Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RevengeHotels

Description

RevengeHotels is a targeted cybercrime campaign that has been active since 2015, primarily targeting hotels, hostels, and tourism companies. The threat actor uses remote access Trojan malware to infiltrate hotel front desks and steal credit card data from guests and travelers. The campaign has impacted hotels in multiple countries, including Brazil, Argentina, Chile, and Mexico. The threat actor employs social engineering techniques and sells credentials from infected systems to other cybercriminals for remote access.

AI Analysis

· 1 week ago

Executive Summary

RevengeHotels is a cybercrime campaign active since 2015, targeting hotels in Latin America to steal credit card data and sell system credentials on the dark web.

Goals & Targeting

The primary goal of RevengeHotels is monetary gain through data theft. They target the hospitality sector, particularly hotels in Latin America, due to their accessible payment systems. Their victims are often mid-sized to large hotels with less sophisticated security measures.

Enhanced Description

RevengeHotels operates by compromising hotel front desk systems using remote access Trojans (RATs) via social engineering campaigns. The malware harvests credit card information from guests and is known for selling stolen credentials to other cybercriminals. Its campaigns have affected multiple countries, including Brazil and Argentina.

Key Capabilities

  • Use of remote access Trojans
  • Social engineering tactics
  • Data theft and credential sale

MITRE ATT&CK Tactics

Initial Access
Credential Access
Lateral Movement

ATT&CK Techniques

T1059
T1078.001
T1021.002

Software / Tooling

Custom Remote Access Trojan (RAT)
Social Engineering Tools
Credential Dumper

Campaigns & Victims

RevengeHotels has demonstrated persistence over years, focusing on hotel systems. They sell stolen data in dark web markets and adapt tactics to target specific system vulnerabilities.

IOC Patterns

  • Spear-phishing emails targeting hotel staff
  • Compromised hotel systems listed for sale online
  • Phishing emails with malicious links sent from new domains

Recommended Actions

  • Implement employee training on social engineering attacks
  • Deploy endpoint detection and response (EDR) solutions
  • Regularly update software to mitigate known vulnerabilities
  • Secure guest data storage and access controls
  • Monitor for suspicious activity in third-party vendor systems
  • Apply multi-factor authentication where possible

Suggested Tags

cybercrime
financial-motivation
hospitality-sector
Latin-America
malware
social-engineering

Confidence Assessment

Confidence level is moderate due to detailed descriptions of TTPs but limited specifics on exact tools and techniques. Data gaps include precise attack vectors beyond social engineering.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
cybercrime
financial-motivation
hospitality-sector
Latin-America
malware
social-engineering

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.