RevengeHotels Leveraging AI To Attack Windows Users With VenomRAT
ID: 083ed7b2-4c4b-590e-a911-10d13b26c21f
STIX ID: report--083ed7b2-4c4b-590e-a911-10d13b26c21f
Feed Name: cybersecurityNews.com
RevengeHotels, a financially motivated threat actor active since 2015, has shifted to using large-language-model–generated JavaScript loaders and PowerShell stagers to deliver VenomRAT to hospitality networks in Latin America; the multi-stage chain decodes and writes timestamped PowerShell scripts, retrieves Base64 payloads to execute VenomRAT in memory, and leverages HVNC, file-stealing modules, UAC bypasses, encrypted/configured C2 communication, and ngrok tunneling to expose remote services—complicating detection and increasing risk to targeted organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
