
25/09/2025
๐๐๐ฌ๐ฉ๐๐ซ๐ฌ๐ค๐ฒ ๐๐๐ซ๐ง๐ฌ ๐๐ซ๐๐ฏ๐๐ฅ๐ฅ๐๐ซ๐ฌ: ๐๐-๐๐จ๐ฐ๐๐ซ๐๐ ๐๐ญ๐ญ๐๐๐ค๐ฌ ๐๐ซ๐ ๐๐๐ซ๐ ๐๐ญ๐ข๐ง๐ ๐๐จ๐ญ๐๐ฅ ๐๐ฎ๐๐ฌ๐ญ๐ฌ
Between June and August 2025, Kasperskyโs Global Research and Analysis Team (GReAT) discovered a new wave of cyberattacks by a threat group called RevengeHotels, which targets hotels to gain access to guestsโ payment information.
The threat actor is now using artificial intelligence to make attacks more effective and reach additional regions.
How the attacks work: the threat actor sends phishing emails directly to hotel staff, often disguised as invoices or job applications. Once a hotel employee interacts with these emails, malware called VenomRAT is installed on the hotelโs systems, giving attackers access to guestsโ payment data and other sensitive information. The emails often look convincing, coming from legitimate-looking websites or Portuguese-themed domain names.