The RevengeHotels hacking campaign is back in full force and targeting the tourism industry .
One of the most frequent targets of hackers is hotels and the tourism industry in general.
Hotels, restaurant chains, and various stores are considered ideal targets because cybercriminals can carry out various attacks and affect a large number of victims. Some of the most common practices of hackers are breaching PoS systems (to collect customer/tourist data), sending phishing emails to staff (which can give access to internal systems), and carrying out Man-in-The-Middle attacks through public WiFi hotspots in hotels.
The data collected by hotels and all related servicesis valuable. It holds a large amount of personal information, such as identity details and financial information, which hackers can use for various scams, such as spear-phishing attacks, selling data, creating clones of customers.
Kaspersky previously described a hacking campaign that included spear-phishing, spyware , and malware targeting hotels. It was called DarkHotel. But yesterday, it published new research on another targeted campaign, called RevengeHotels.
It was first detected in 2015, but most of the attacks have taken place this year. So far, 20 victims have been found. The main targets are hotels, guesthouses, and companies hospitality and tourism
The RevengeHotels campaign has affected hotels in Argentina, Bolivia, Chile, Costa Rica, France, Italy, Portugal, Mexico, Spain, Turkey, and Thailand. However, most of the attacks have taken place in Brazil.
The hackers behind the campaign breach hotel systems and use trojans to steal customers' credit card details as well as other financial and personal information, which hotels receive from third-party companies, such as booking sites (e.g. Booking.com).
The attack usually starts with a phishing email sent to hotels (or other hospitality services). According to researchers, hackers send emails that are very carefully crafted and detailed to appear legitimate. They imitate real and reputable companies.
These emails contain malicious Word, Excel, or PDF documents, which exploit CVE-2017-0199, a Microsoft Office RCE vulnerability.

If a vulnerable system is detected, VBS or PowerShell scripts to exploit the bugs and lead to the deployment of RevengeRAT, NjRAT, NanoCoreRAT, 888 RAT, ProCC and other malicious programs.
The Trojans invade infected computers, creating “tunnels” that connect the computer to the attackers’ command-and-control (C2) server. The hackers have also created another feature, ScreenBooking, which is used to capture payment card information.
According to the researchers, the initial versions of the trojans in the RevengeHotels campaign included two functions. A backdoor and a function for taking screenshots. “We recently observed that these functions have been merged into a single backdoor, capable of collecting data from the clipboard and capturing screenshots.”
In addition to the RevengeHotels hackers, Kaspersky also uncovered another group, ProCC, which also targets the tourism sector. The ProCC group uses a more sophisticated backdoor that steals more information.
“If you want to stay safe when traveling, it is recommended to use a virtual payment card for bookings through OTAs, as these cards usually expire after one charge,” says Kaspersky. “When paying for your hotel, it is a good idea to use a virtual wallet such as Apple Pay, [or] Google Pay. If that is not possible, use a secondary or less important credit card, as you cannot know if the hotel’s system is clean.”
