Not-so-safe travels

1 November 2019

Kaspersky’s research of the RevengeHotels campaign aimed at the hospitality sector, has confirmed over 20 hotels in Latin America, Europe and Asia have fallen victim to targeted malware attacks. Even more hotels are potentially affected across the globe. Travellers’ credit card data, which is stored in a hotel administration system, including those received from online travel agencies (OTAs), is at risk of being stolen and sold to criminals worldwide.

RevengeHotels is a campaign that includes different groups using traditional Remote Access Trojans (RATs) to infect businesses in the hospitality sector. The campaign has been active since 2015 but has gone on to increase its presence in 2019. At least two groups, RevengeHotels and ProCC, were identified to be part of the campaign, however more cybercriminal groups are potentially involved.

The main attack vector in this campaign is emails with crafted malicious Word, Excel or PDF documents attached. Some of them exploit CVE-2017-0199, loading it using VBS and PowerShell scripts and then installing customised versions of various RATs and other custom malware, such as ProCC, on the victim’s machine that could later execute commands and set up remote access to the infected systems.

Each spear-phishing email was crafted with special attention to detail and usually impersonating real people from legitimate organisations making a fake booking request for a large group of people. It is worth noting that even careful users could be tricked to open and download attachments from such emails as they include an abundance of details (for instance, copies of legal documents and reasons for booking at the hotel) and looked convincing. The only detail that would reveal the attacker would be a typosquatting domain of the organisation.

Once infected, the computer could be accessed remotely not just by the cybercriminal group itself — evidence collected by Kaspersky researchers shows that remote access to hospitality desks and the data they contain is sold on criminal forums on a subscription basis. Malware collected data from hospitality desk clipboards, printer spoolers and captured screenshots (this function was triggered using specific words in English or Portuguese). Because hotel personnel often copied clients’ credit card data from OTAs in order to charge them, that data could also be compromised.

Kaspersky telemetry confirmed targets in Argentina, Bolivia, Brazil, Chile, Costa Rica, France, Italy, Mexico, Portugal, Spain, Thailand and Turkey. However, based on data extracted from Bit.ly, a popular link shortening service used by the attackers to spread malicious links, Kaspersky researchers assume that users from many other countries have at least accessed the malicious link – suggesting that the number of countries with potential victims could be higher.

“As users grow wary of how protected their data truly is, cybercriminals turn to small businesses, which are often not very well protected from cyberattacks and possess a concentration of personal data. Hoteliers and other small businesses dealing with customer data need to be more cautious and apply professional security solutions to avoid data leaks that could potentially not only affect customers, but also damage hotel reputations as well,” comments Dmitry Bestuzhev, head of Kaspersky’s Global Research and Analysis Team.

To stay safe, travellers are advised to:

Use a virtual payment card for reservations made via OTAs, as these cards normally expire after a single charge.

When paying for a reservation or checking out at hotel desks, use a virtual wallet, such as Apple Pay or Google Pay, or a secondary credit card with a limited amount of debit available.

Hotel owners and management are also advised to follow these steps to secure customer data:

Conduct risk assessments of the existing network and implement regulations regarding how customers’ data is handled.

Use a reliable security solution with web protection and application control functionality, such as Kaspersky Endpoint Security for Business.

Introduce staff security awareness training to teach employees how to spot spear-phishing attempts and show the importance of remaining vigilant when working with incoming emails.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Wireless home surveillance
Smart Home Automation
EZVIZ has launched its AOV software alongside the X5S large-capacity storage solution, providing a 360-degree security solution with real-time footage of incidents and recorded evidence when needed.

Read more...
Wi-Fi security camera with PIR
Ajax Systems Smart Home Automation
Ajax Systems has introduced the IndoorCam, designed for private households, small offices, and small to medium businesses, equipped with a 4 MP camera, HDR, and IR illumination of up to 8 m.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...
A passport to offline backups
SMART Security Solutions Technews Publishing Editor's Choice Infrastructure Smart Home Automation
SMART Security Solutions tested a 6 TB WD My Passport and found it is much more than simply another portable hard drive when considering the free security software the company includes with the device.

Read more...
DoorBell with built-in AI
Ajax Systems Access Control & Identity Management Products & Solutions Smart Home Automation
Ajax Systems has announced the release of Ajax DoorBell, which features built-in AI, an IR sensor, and app control, seamlessly integrating into the Ajax ecosystem to ensure efficiency and security confidence.

Read more...
Kaspersky warns of active Docusign-themed phishing scams
Kaspersky Information Security
Kaspersky is warning of a rising phishing scam involving fraudulent emails pretending to be from Docusign, a globally used e-signature platform, where users are asked to enter a work login and password credentials.

Read more...
Stay safe while using AI assistants
Kaspersky Information Security News & Events AI & Data Analytics
The new DeepSeek AI assistant has attracted a lot of attention, including the interest of cybercriminals. Kaspersky experts have detected scam activity related to it.

Read more...
Organisations fear AI-driven cyberattacks, but lack key defences
Kaspersky Information Security News & Events Training & Education
A recent Kaspersky study reveals that businesses are increasingly worried about the growing use of artificial intelligence in cyberattacks, with 56% of surveyed companies in South Africa reporting a rise in cyber incidents over the past year.

Read more...
Know who’s spying on you
Kaspersky Information Security Products & Solutions
According to the latest State of Stalkerware report, 40% of the people surveyed worldwide stated they have experienced stalking or suspect they are being spied on. A solution for Android is now available.

Read more...
Dahua launches 2-wire hybrid video intercom system
Dahua Technology South Africa Smart Home Automation Access Control & Identity Management Residential Estate (Industry)
Dahua Technology has launched a 2-Wire Hybrid Video Intercom System (the Dahua EACH Series) that redefines residential security and communication with its high image quality and easy deployment features.

Read more...