CANVAS METRO EDITION
Friday, September 18, 2026
Magicgame.Metro
AI & ML

Cybercriminal Group TA558 Revamps Tactics Targeting Travelers with Malicious Reservation Links

Published Aug 22, 2022 Reads 312 Desk Nate Nelson

TA558 has intensified its cyberattacks on the travel sector, using deceptive reservation links to deliver malware payloads as travel rebounds.

Cybercriminal Group TA558 Revamps Tactics Targeting Travelers with Malicious Reservation Links

As travel rebounds post-pandemic, a notorious threat group known as TA558 has ramped up its cyberattacks, targeting weary travelers already beset by flight cancellations and overbooked hotels. With a newfound focus, TA558 aims to exploit the surge in travel-related activity by deploying phishing tactics that lead unsuspecting victims into malware traps. Their strategies revolve around the psychological vulnerabilities of individuals who are already frustrated and stressed by travel-related issues—essentially adding another layer of chaos to an already challenging experience.

New Tactics in Cybercrime

Security experts report that TA558 has updated its strategies, reviving tactics from 2018 with a disturbing twist: they now distribute fake reservation emails embedded with links that deliver various forms of malware. The latest report from Proofpoint highlights the shift towards using RAR and ISO file attachments. These compressed files, when executed, extract and unleash harmful code, amplifying the risks for unsuspecting targets. Malware delivered via these methods can often go unnoticed because users might not be keen on the technicalities of file extensions—they may assume a compressed file from a seemingly legitimate email is perfectly safe.

According to Proofpoint, the group has dramatically increased its activity in 2022, launching 27 new campaigns incorporating URLs into their strategies. This is a striking rise from just five campaigns during the prior three years, illustrating the group’s evolving approach to cybercrime. Often, these URLs lead to files packed with executables waiting for activation by the victim. The uptick in campaigns signals a calculated attempt to adapt to the current state of remote work and increased digital vulnerability as more travelers turn to online services to secure their plans.

Malicious Links that Lead to Malware

Once a victim clicks on the deceptive reservation link, they may inadvertently decompress an ISO file harboring a batch file. Executing this file triggers a PowerShell script responsible for downloading a follow-up payload like AsyncRAT, a remote access trojan. This multi-step process is particularly insidious, as it employs typically benign file types that users are less inclined to regard as threats.

This is not the first instance of TA558 using malware; prior campaigns have seen them employ different tactics, such as embedding malicious Microsoft Word document attachments. The transition to using ISO and RAR files aligns with broader industry changes, particularly Microsoft’s move to disable macros by default in Office applications. This shift likely explains why the group incorporated these compressed files as a means to bypass traditional defenses. It’s a strategic pivot that guarantees higher success rates in infiltrating networks.

As noted by researchers, the tempo of TA558's campaigns picked up considerably last year, delivering a mix of malware variants such as Loda RAT, Revenge RAT, and AsyncRAT via diverse delivery methods including URLs and file attachments. These payloads often focus on remote access, enabling extensive reconnaissance and data theft activities. Such capabilities can allow criminals to linger undetected in systems, siphoning sensitive information over long periods, which poses significant risks for both businesses and their clients.

Despite these shifts in tactics, TA558's primary aim remains financial gain. Proofpoint analysts have high confidence that the group monetizes stolen data, presenting risks to both organizations in the travel industry and their customers, according to Sherrod DeGrippo, the vice president of threat research and detection at Proofpoint. This isn’t just a nuisance; it can lead to profound reputational damage, operational disruptions, and legal inquiries for affected firms.

Background on TA558

TA558 has had its sights set on the travel, hospitality, and associated sectors since at least 2018. While primarily targeting organizations in Latin America, their operations have spread to North America and parts of Western Europe. Their geographical targeting reflects a growing trend where cybercriminals look beyond their localities to more lucrative markets.

Historically, TA558 has relied on social engineering tactics, crafting emails that look legitimate to lure victims into clicking dangerously disguised links or documents. Their emails are typically written in Spanish or Portuguese, often concerning fictitious hotel bookings. For instance, many have used subject lines containing simply the word “reserva.” This tactic exploits linguistic familiarity, further enabling them to evade suspicion from potential victims.

Their earlier campaigns exploited vulnerabilities in Microsoft Word, such as the CVE-2017-11882 flaw, which allowed them to download RATs like Loda or Revenge RAT directly onto the target's machine. As they evolved, they expanded tactics from using macros in Office documents to include malicious PowerPoint and template injections, even branching out to English-speaking demographics. This indicates their willingness to diversify and reach a wider audience, marking a significant evolution in their operational strategy.

The peak of TA558's activity occurred in early 2020, with January alone seeing 25 distinct phishing campaigns. This surge often involved the use of macro-laden Office documents and leveraging known vulnerabilities. Interestingly, as travel begins to normalize, their resurgence in activity suggests that they are capitalizing on newly vulnerable populations.

Implications and Future Outlook

Researchers remain firm in their warning: organizations operating in the travel sector, especially those in Latin America, North America, and Western Europe, should remain vigilant and informed about TA558's evolving tactics and operational procedures. If you're working in this space, neglecting these threats could have disastrous consequences. The evolving strategies employed by TA558 serve as a poignant reminder of the need for heightened cybersecurity measures in our increasingly digitally dependent world.

As the travel industry recuperates from pandemic-induced strains, it’s clear that the nexus between increased travel volume and rising cyber threats will require constant vigilance from stakeholders. Organizations must adopt a proactive security approach, including employee training on recognizing phishing attempts, robust email filtering, and ongoing threat intelligence monitoring. The stakes are high, and as travel heats up, TA558 is a formidable adversary waiting to exploit any lapses in defense.

Source: Nate Nelson · threatpost.com

Discussion

Sign in to join the discussion.