The RevengeHotels cybercrime group is steadily raising the bar of its technological maturity: researchers are now detecting the integration of code automatically generated (from large language models) in the infection chain, which transforms old phishing tactics into more "industrial" and difficult-to-detect attacks.

The group was initially known for targeted phishing attacks targeting hotel front desks and delivering RATs such as RevengeRAT or NanoCore. The group's activity now shows a clear shift towards multi-stage, in-memory attacks: dynamically generated JavaScript loaders that write and execute temporary PowerShell stubs, which in turn decrypt and load into memory the VenomRAT — an implant based on open source but enhanced with HVNC, file theft , and UAC bypass functionality. These techniques drastically reduce the disk footprint and make traditional signature-based detections difficult.
See also: A simple text file led to Akira Ransomware attacks
RevengeHotels: New Attacks – VenomRAT Distribution
What stands out about the latest RevengeHotels attacks is the “professional” look of the generated code: detailed comments, placeholder variables, and consistent structure suggest automated composition by LLM agents — a development that allows the attacker to rapidly scale the production of loaders with small variations that bypass detection rules. The use of unique, timestamped filenames and storage in a format that changes with each execution indicate that the operators are aiming for the long-term survival of their campaigns.
Geographically, the latest campaigns appear to be heavily targeting Latin America, with a focus on Brazil and Spanish-speaking markets, where the bait is presented in Portuguese or Spanish — typically as notifications of overdue invoices or fake job applications. The emails direct victims to domains hosting scripts named in the rotating “Fat{NUMBER}.js” format— which means “invoice” in Portuguese — to initiate the download process.

The multi-stage techniques used by attackers are designed to circumvent both technical and operational obstacles. The loader decodes an obfuscated buffer, writes a PowerShell file with a timestamped filename, and then retrieves two main payloads — a lightweight loader and the implant itself (VenomRAT) — ultimately executing the RAT in memory without leaving a persistent executable on disk. This “fileless” approach reduces visibility to traditional EDR/AV tools.
See also: RaccoonO365: Microsoft & Cloudflare dismantle phishing network
Leveraging LLMs at the code generation stage isn’t just impressive — it’s problematic for security: research and reports show that automatic code generation introduces vulnerabilities and accelerates the rate at which attackers experiment with new variables and variations. Security analysts warn that these models offer criminals access to “generators” of working, maintainable, and mutable code, reducing development costs and increasing the speed of attack execution.
What does this mean for hotel security managers and network administrators in general? First, that traditional signature-only policies need to be supplemented by behavioral detection and in-memory execution monitoring. Second, that training staff to recognize more “structured” and persuasive phishing emails — which contain fewer spelling errors and more professional language — is more critical than ever. Third, businesses need to harden the isolation of front-desk systems, restrict script execution permissions , and implement robust logging and network segmentation settings.
See also: Hackers stole customer data from Gucci, Balenciaga and Alexander McQueen

Finally, the phenomenon raises a broader ethical-technological question: the same technologies that promise faster software production and automation — LLMs — can also facilitate the production of malware. The answer should be twofold: technical (EDR enhancements, monitoring, segmentation) and political (regulatory guidelines for the use of generative code, best practices against AI-produced code). Until detection methods evolve, hosting providers — and every organization — must assume that attackers will continue to automate and scale their attacks.
This new phase of RevengeHotels is not just a change of tools: it is a warning that the combination of human manipulation with automated AI capabilities creates attacks that require a new approach to defense — faster, more agile, and with an emphasis on behavioral detection rather than static signature.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
