惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
D
Docker
GbyAI
GbyAI
Y
Y Combinator Blog
Google DeepMind News
Google DeepMind News
G
Google Developers Blog
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
小众软件
小众软件
Engineering at Meta
Engineering at Meta
酷 壳 – CoolShell
酷 壳 – CoolShell
I
InfoQ
B
Blog
H
Help Net Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
B
Blog RSS Feed
Microsoft Security Blog
Microsoft Security Blog

The Register - Security: Research

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits Extortion crews have their eyes on high-value AI data, Google warns Researcher shows how Claude Code can be tricked simply by asking it to summarize a website Copilot tricked into telling reseachers how to hack itself Akira ransomware scum blocked victim How the famed USENIX Security conf is managing a flood of papers in the AI era www.theregister.com Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine ChatGPT blindly trusts browser content, turning the page into a payload Russia-linked threat group put ChatGPT to work from lure to payload Kids can bypass some age checks with a drawn-on mustache What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia ORNL builds more sensitive GPS interference detector Researchers find sabotage malware that may predate Stuxnet Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus Anthropic, Google, Microsoft paid AI bug bounties – quietly Security reserchers tricked Apple Intelligence into cursing Don't open that WhatsApp message, Microsoft warns Security boffins harvest bumper crop of API keys from web Lightning-fast exploits mean patch fast, says Cisco Talos AI agents are 'gullible' and easy to turn into your minions Smooth criminals talking their way into cloud environments, Google says Snoops plant info-stealing malware on iPhones, Google warns Cybercrime up 245% since the start of the Iran war Rogue AI agents can work together to hack systems Fake applicants are sending security-killing malware AI agent hacked McKinsey chatbot for read-write access Kaspersky: No signs Coruna iPhone exploit kit made by US
Kaspersky: RevengeHotels returns with AI-coded malware
Carly Page · 2025-09-23 · via The Register - Security: Research

Research

Old hotel scam gets an AI facelift, leaving travellers’ card details even more at risk

Kaspersky has raised the alarm over the resurgence of hotel-hacking outfit "RevengeHotels," which it claims is now using artificial intelligence to supercharge its scams.

Between June and August this year, Kaskersky Global Research and Analysis Team (GReAT) found the group deploying malware with AI-generated code, making its intrusions harder to detect and far more effective.

The core playbook remains familiar: phishing emails, disguised as booking requests or job applications, land in the inboxes of hotel staff. Once opened, they deliver a remote access trojan known as VenomRAT, giving attackers control of the infected machine and a path to guests' card data and other personal details. 

REG AD

While the social engineering may be old-school, the malware's AI-crafted underpinnings represent a troubling leap in sophistication, Kaspersky says. 

REG AD

"Cybercriminals are increasingly using AI to create new tools and make their attacks more effective. This means that even familiar schemes, like phishing emails, are becoming harder to spot for a common user," said Lisandro Ubiedo of Kaspersky's GReAT team.

"For hotel guests, this translates into higher risks of card and personal data theft, even when you trust well-known hotels."

The Russian cybersecurity firm says that Brazil has so far borne the brunt of the latest wave of RevengeHotel attacks, but notes that incidents have already surfaced elsewhere. 

The group's use of AI-generated code marks a shift from RevengeHotels' previous campaigns, which relied on cookie-cutter malware and crude phishing. By leaning on auto-generated code, the crew can churn out fresh-looking variants that slip past older security tools, yet are simple enough to include a bog-standard phishing email. For hotel IT staff, that means the tricks look familiar, but the malware buried inside is far harder to spot and shut down.

Kaspersky's recommended defences will be familiar to any security pro: hotels should train staff to recognise suspicious emails, adjust spam filters, and deploy endpoint detection tools that can flag infections early. Travellers, meanwhile, can limit exposure by monitoring card activity closely or using virtual payment methods where possible.

RevengeHotels isn't new to this game. The group has been active for more than a decade, targeting hotels, hostels and other tourism outfits since 2015. Besides skimming card details, they've been flogging access to compromised property systems on dark-web markets so other crooks can swoop in and run scams. ®