Tag: TA558

TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks
News

TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks

The threat actor identified as TA558 has been implicated in a new round of assaults that target hotels in Spanish-speaking markets and Brazil by distributing several remote access trojans (RATs), such as Venom RAT. The behavior, which was noticed in the summer of 2025, is being linked by Russian cybersecurity outfit Kaspersky to a cluster it calls RevengeHotels. Venom RAT implants are still being distributed by the threat actors using JavaScript loaders and PowerShell downloaders through phishing emails with invoice themes, the organization stated. This campaign appears to use large language model (LLM) agents to produce a huge amount of the initial infector and downloader code. The results show a new tendency among cybercriminal organizations to use artificial intelligence (AI) ...
TA558 Hackers Weaponize Images for Wide-Scale Malware Attacks
News

TA558 Hackers Weaponize Images for Wide-Scale Malware Attacks

The threat actor identified as TA558 has been seen to distribute a variety of malware, including Agent Tesla, FormBook, Remcos RAT, LokiBot, GuLoader, Snake Keylogger, and XWorm, among others, by using steganography as an obfuscation tactic. According to a study released on Monday by the Russian cybersecurity company Positive Technologies, "the group made extensive use of steganography by sending VBSs, PowerShell code, as well as RTF documents with an embedded exploit, inside images and text files." Because of its dependence on steganography and the use of file names like greatloverstory.vbs and easytolove.vbs, the campaign has been dubbed SteganoAmor. While businesses in Russia, Romania, and Turkey have also been singled out, the bulk of the attacks have targeted Latin American ...