RevengeHotels
· Published 21/12/2025 16:10 · Modified 21/12/2025 16:10
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 16:10
- Modified
- 21/12/2025 16:10
- Updated at
- 21/12/2025 16:10
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 16 attack patterns (mitre), 9 malware, 1 sectors, 9 countries, 1 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
1 CVE 14 MITREs 11 Malwares 1 APTPublished 16/09/2025 13:41 · Modified 16/09/2025 14:10
Attack patterns (MITRE) (16)
-
T1553.005 usesMark-of-the-Web Bypass
-
T1566 usesPhishing
-
T1021.005 usesVNC
-
T1070.001 usesClear Windows Event Logs
-
T1204 usesUser Execution
-
T1574.002 uses
-
T1571 usesNon-Standard Port
-
T1091 usesReplication Through Removable Media
-
T1059.007 usesJavaScript
-
T1562.001 usesDisable or Modify Tools
-
T1112 usesModify Registry
-
T1055 usesProcess Injection
-
T1027 usesObfuscated Files or Information
-
T1021.001 usesRemote Desktop Protocol
-
T1059.001 usesPowerShell
-
T1140 usesDeobfuscate/Decode Files or Information
Malware (9)
-
njRAT - S0385 usesFamilyPublished 16/09/2025 13:41 · Modified 16/09/2025 13:41
-
XWorm usesFamilyPublished 27/03/2026 08:45 · Modified 27/03/2026 08:45
-
RevengeRAT usesFamilyPublished 16/09/2025 13:41 · Modified 16/09/2025 13:41
-
NanoCoreRAT usesFamilyPublished 16/09/2025 13:41 · Modified 16/09/2025 13:41
-
DesckVBRAT usesFamilyPublished 16/09/2025 13:41 · Modified 16/09/2025 13:41
-
ProCC usesFamilyPublished 16/09/2025 13:41 · Modified 16/09/2025 13:41
-
888 RAT usesFamilyPublished 16/09/2025 13:41 · Modified 16/09/2025 13:41
-
VenomRAT usesFamilyPublished 03/06/2026 13:18 · Modified 03/06/2026 13:18
-
NJRat usesFamilyPublished 05/03/2025 11:12 · Modified 05/03/2025 11:12
Sectors (1)
- Hospitality targets
Countries (9)
- Brazil targets
- Russian Federation targets
- Argentina targets
- Bolivia, Plurinational State of targets
- Mexico targets
- Belarus targets
- Costa Rica targets
- Chile targets
- Spain targets
Vulnerabilities (CVE) (1)
CVE-2017-0199
KEV
7.8
High
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for …
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 12/04/2017
- Modified
- 22/04/2026