HomeSecurityHackers target hotels and infect systems with malware

Hackers target hotels and infect systems with malware

A group of hackers tracked as TA558 is conducting phishing campaigns targeting numerous hotels and companies in the hospitality and travel space with the aim of infecting them with malware. The attackers are using a set of 15 different malware , which are usually remote access trojans (RATs). Using these malware, they can gain access to the target systems, spy on users, steal key data, and extort money from the hotel/company’s customers.

Hacker hotels

The TA558 group has been active since at least 2018, but Proofpoint has noticed increased activity now, likely linked to the recovery of tourism after two years of restrictions due to COVID-19.

See also: Official response from DESFA to the cyberattack!

TA558's phishing campaigns

In 2022, TA558 hackers stopped using documents with malicious macros in their phishing campaigns and adopted RAR and ISO file attachments or embedded URLs in messages.

This change (which was also noticed by other hacking groups) comes in response to Microsoft to block macros in Office, which hackers have always used to load and install malware through malicious documents.

The TA558 hackers' phishing emails are written in English, Spanish, and Portuguese and target travel companies and hotels in North America, Western Europe, and Latin America.

Hackers target hotels and infect systems with malware

The themes of phishing emails revolve around making a reservation at the target company and are purported to come from conference organizers, travel agents, and other sources that recipients cannot easily dismiss.

As we said, hackers are now using URLs embedded in messages. Victims who click on the URL in the body of the message (an address that is supposed to be a booking link) will receive an ISO file from a remote resource.

See also: 35 Android malware apps found in Google Play Store

The file contains a batch file that launches a PowerShell script that ultimately installs the RAT payload on the victim's computer and creates a scheduled task for persistence.

In most of the phishing attacks that Proofpoint observed this year, the payload was AsyncRAT or Loda, while Revenge RAT, XtremeRAT, CaptureTela, and BluStealer were also deployed on a smaller scale. For example, a recent campaign used QuickBooks invoices as bait instead of room reservations and infected systems exclusively with Revenge RAT.

After compromising hotel systems with RAT malware, TA558 hackers move deeper into the network to steal customer data, store credit card details, and modify customer-facing websites to divert booking payments.

In July 2022, the Booking.com account of The Marino Boutique Hotel in Lisbon, Portugal , and the attacker stole €500,000 over four days from unsuspecting guests who paid to book a room. It is unclear whether the TA558 group is related to the above attack (nothing has been proven). However, the attack methods match those of these hackers. This attack clearly shows how attackers could generate revenue from their access to hotel systems.

See also: NSO Group: Pegasus creator changes CEO and plans layoffs

malware

Additionally, TA558 hackers could make money by selling or using stolen credit card details, selling personal information, blackmailing high-profile individuals, or selling access to the network to ransomware gangs.

The increased activity of this group may be due to the resumption of tourism activities. COVID-19 pandemic restrictions around the world were less strict during the summer and many people began to travel.

Since 2018, TA558 has been an active threat actor targeting the hospitality and travel industries and other industries related to these sectors.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS