Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Since 2018, security researchers tracked a financially-motivated cybercrime actor, TA558, targeting hospitality, travel, and related industries located in Latin America and sometimes North America, and western Europe. The actor sends malicious emails written in Portuguese, Spanish, and sometimes English. The emails use reservation-themed lures with business-relevant themes such as hotel room bookings. The emails may contain malicious attachments or URLs aiming to distribute one of at least 15 different malware payloads.

AI Analysis

· 1 week ago

Executive Summary

TA558 is a financially motivated cybercrime actor targeting hospitality and travel industries in Latin America, North America, and Western Europe since 2018. The group uses phishing emails with malicious attachments or URLs, often themed around hotel bookings, to distribute malware.

Goals & Targeting

TA558 appears to prioritize financial gain, with targeting focused on industries where quick monetary gains can be achieved through data theft or ransomware deployment. The choice of Latin American targets may reflect lower defensive postures and higher susceptibility to such attacks. This actor's strategic focus on hospitality and travel sectors indicates a keen understanding of these industries' vulnerabilities and their reliance on digital communications.

Enhanced Description

TA558 has emerged as a persistent cybercrime threat focusing on the hospitality and travel sectors. The actor leverages multi-language phishing campaigns, utilizing Portuguese, Spanish, and English languages to target victims more effectively across diverse regions. These emails often mimic legitimate business communications related to hotel reservations, creating a sense of urgency or relevance for recipients in targeted industries. Malicious payloads delivered through such campaigns include at least 15 distinct malware variants, highlighting the group's capability to adapt and employ varied attack vectors. The targeting of Latin America suggests either regional operational focus or strategic efforts to exploit weaker cybersecurity frameworks in this area.

Key Capabilities

  • Phishing emails with malicious attachments
  • Distribution of multiple malware payloads
  • Multi-language communication
  • Targeted sector focus

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion

Software / Tooling

Various malware (at least 15 types)

Campaigns & Victims

TA558's campaigns are characterized by spear-phishing emails with attachment-based payloads. The actor has been observed targeting smaller businesses in the hospitality sector, likely due to weaker defenses and easier exploitation. Notable operations include large-scale phishing campaigns during peak travel seasons, suggesting an operational rhythm tied to specific industry cycles.

IOC Patterns

  • Spear-phishing emails with hotel booking themes
  • Malicious Office document attachments
  • Phishing URLs leading to malware downloads

Recommended Actions

  • Implement robust email filtering and endpoint detection solutions
  • Conduct regular user training on phishing awareness
  • Monitor for suspicious activity in reservation systems
  • Verify the authenticity of external communications

Suggested Tags

Financially motivated
Hospitality sector
Latin America

Confidence Assessment

Confidence level is moderate. While TA558's basic TTPs are known, details on exact malware families, specific campaigns, and operational infrastructure remain unclear. Additional intelligence sourcing could enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Healthcare Targeting
Phishing
Financially motivated
Hospitality sector
Latin America

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.