Cybercriminal group TA558 has intensified its phishing attacks on the travel sector, utilizing new methods to deliver malware through fake reservation links.

As travelers return to the skies and hotels, a significant cyber threat looms large, with the notorious TA558 group stepping up its phishing campaigns against the travel and hospitality sectors. This uptick comes after a brief period of dormancy, likely prompted by the pandemic-induced travel restrictions.
Security experts have observed that TA558 has modernized its tactics since its initial campaigns, especially its use of deceptive reservation emails designed to lure unsuspecting victims into downloading malicious files. Reports indicate that this group has notably shifted from traditional phishing methods to incorporating RAR and ISO file attachments, which users must execute to expose their host systems to various malware strains.
Proofpoint's recent findings illustrate the scale of this resurgence. The group executed 27 campaigns involving URLs in 2022 alone, a stark contrast to just five from 2018 to 2021. Typically, these malicious links direct users to compressed files, including ISOs and RAR files containing executable malware. The execution of these files often leads to the deployment of powerful payloads like AsyncRAT, which grants unauthorized remote access to compromised machines.
From Reservation to Infection
Historically, TA558 has exploited vulnerabilities in Microsoft Office programs, particularly through malicious Word documents. Earlier tactics involved using remote template URLs or macros—strategies that have evolved due to Microsoft’s changes in security protocols. The group has now adapted to deliver its malware through methods that bypass these defenses, opting for compressed file formats such as ISO and RAR, which became more prevalent as traditional entry methods were fortified.
Proofpoint notes that the shift in strategy likely coincides with security enhancements by Microsoft, aimed at disabling macros by default in its Office suite. “The journey from a benign-looking reservation link to a malicious payload requires users to decompress and run a batch file embedded within the ISO,” researchers explained.
TA558's latest campaigns are not only more numerous but also increasingly sophisticated, with malware delivery mechanisms becoming more varied. Recent campaigns include remote access trojans (RATs) such as Loda, Revenge RAT, and AsyncRAT, enabling cybercriminals to engage in reconnaissance, steal data, and distribute further malicious payloads.
Experts have high confidence in classifying TA558 as a financially motivated group. Their campaigns are not just targeting businesses in the travel sector but are also poised to compromise customer data, leading to potential identity theft and financial losses. Sherrod DeGrippo, a leading researcher at Proofpoint, emphasized, “This actor’s activities pose significant risks not only to travel organizations but also to their customers.”
An Overview of TA558’s Activities
Since at least 2018, TA558 has honed in on travel and hospitality companies, predominantly targeting organizations across Latin America, with known forays into North America and Western Europe. The group's phishing emails, frequently composed in Portuguese or Spanish, have evolved over the years, initially leaning heavily on the promise of hotel reservation confirmations to bait victims.
In its early days, TA558 relied on well-documented vulnerabilities like CVE-2017-11882 to ensnare users into executing malicious code, leading to infections from RATs such as Loda or Revenge RAT. Their tactics diversified in 2019 with the incorporation of macro-savvy PowerPoint files, expanding their reach to English-speaking victims.
The early months of 2020 marked a peak for TA558, showcasing relentless activity with 25 malicious campaigns launched just in January. This aggressive approach primarily revolved around exploiting macro-laden Office documents. Researchers continue to urge organizations, particularly those within TA558’s crosshairs, to examine their security protocols and stay vigilant against this evolving threat.
In summary, organizations in all targeted sectors should remain acutely aware of TA558's methods and adapt their cybersecurity measures accordingly. Understanding these tactics could be pivotal in mitigating the risks posed by this relentless adversary.
Discussion
Sign in to join the discussion.