Since 2018, security researchers tracked a financially-motivated cybercrime actor, TA558, targeting hospitality, travel, and related industries located in Latin America and sometimes North America, and western Europe. The actor sends malicious emails written in Portuguese, Spanish, and sometimes English. The emails use reservation-themed lures with business-relevant themes such as hotel room bookings. The emails may contain malicious attachments or URLs aiming to distribute one of at least 15 different malware payloads.
Executive Summary
TA558 is a financially motivated cybercrime actor targeting hospitality and travel industries in Latin America, North America, and Western Europe since 2018. The group uses phishing emails with malicious attachments or URLs, often themed around hotel bookings, to distribute malware.
Goals & Targeting
TA558 appears to prioritize financial gain, with targeting focused on industries where quick monetary gains can be achieved through data theft or ransomware deployment. The choice of Latin American targets may reflect lower defensive postures and higher susceptibility to such attacks. This actor's strategic focus on hospitality and travel sectors indicates a keen understanding of these industries' vulnerabilities and their reliance on digital communications.
Enhanced Description
TA558 has emerged as a persistent cybercrime threat focusing on the hospitality and travel sectors. The actor leverages multi-language phishing campaigns, utilizing Portuguese, Spanish, and English languages to target victims more effectively across diverse regions. These emails often mimic legitimate business communications related to hotel reservations, creating a sense of urgency or relevance for recipients in targeted industries. Malicious payloads delivered through such campaigns include at least 15 distinct malware variants, highlighting the group's capability to adapt and employ varied attack vectors. The targeting of Latin America suggests either regional operational focus or strategic efforts to exploit weaker cybersecurity frameworks in this area.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
TA558's campaigns are characterized by spear-phishing emails with attachment-based payloads. The actor has been observed targeting smaller businesses in the hospitality sector, likely due to weaker defenses and easier exploitation. Notable operations include large-scale phishing campaigns during peak travel seasons, suggesting an operational rhythm tied to specific industry cycles.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence level is moderate. While TA558's basic TTPs are known, details on exact malware families, specific campaigns, and operational infrastructure remain unclear. Additional intelligence sourcing could enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics