Darkhotel

๐Ÿ”ด High
Also known as: APT-C-06, APT-C-60, ATK52, Dark Hotel, Darkhotel, DarkHotel, darkhotel, Darkhotel - APT-C-06, DUBNIUM, Dubnium, Dubnium (Microsoft), Egobot, Fallout Team, G0012, Karba, Luder, Nemim, Nemin, PALADIN, Pioneer, Purple Pygmy, SHADOW CRANE, Shadow Crane, SIG25, SIG25 (NSA), T-APT-02, Tapaoux, Tardigrade Spider, TEMPLAR, TieOnJoe, TUNGSTEN BRIDGE, Zigzag Hail

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The groupโ€™s name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks. Kaspersky Darkhotel Securelist Darkhotel Aug 2015 Microsoft Digital Defense FY20 Sept 2020

๐ŸŒ Country South Korea
๐Ÿ“… Activity 2014 โ€” 2017
โšก Risk Level High
๐ŸŽฏ Incident Type Espionage
๐Ÿงญ ATT&CK G0012
Private sector
2014
2017

Introduction

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The groupโ€™s name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks. Kaspersky Darkhotel Securelist Darkhotel Aug 2015 Microsoft Digital Defense FY20 Sept 2020

Activities and Tactics

Targeted Sectors: Private sector

Country of Origin: ๐Ÿ‡ฐ๐Ÿ‡ท South Korea

Risk Level: High

First Seen: 2014

Last Activity: 2017

Incident Type: Espionage

Suspected Victims: Japan, Russia, Taiwan, South Korea, China

Notable Campaigns

  • Daybreak?
  • Fallout Team
  • WizardOpium

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 7 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • Inexsmar:
  • Higaisa:
  • Win32.Karba:
  • Win32.Pioneer:
  • CVE-2015-8651:
  • Asruex:
  • CVE-2012-0158:
  • CVE-2010-2883:
  • CVE-2016-4171 and CVE-2018-817:

Attribution and Evidence

Country of Origin: South Korea Additional attribution information pending cataloguing.

References

[1] mitre-attack [5] Securelist Darkhotel Aug 2015 Kaspersky Labโ€™s Global Research & Analysis Team. (2015, August 10). Darkhotelโ€™s attacks in 2015. Retrieved November 2, 2018. [6] Kaspersky Darkhotel Kaspersky Labโ€™s Global Research and Analysis Team. (2014, November). The Darkhotel APT A Story of Unusual Hospitality. Retrieved November 12, 2014. [7] Microsoft Digital Defense FY20 Sept 2020 Microsoft . (2020, September 29). Microsoft Digital Defense Report FY20. Retrieved April 21, 2021. [8] Microsoft Threat Actor Naming July 2023 Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023. [9] Microsoft DUBNIUM July 2016 Microsoft. (2016, July 14). Reverse engineering DUBNIUM โ€“ Stage 2 payload analysis . Retrieved March 31, 2021. [10] Microsoft DUBNIUM Flash June 2016 Microsoft. (2016, June 20). Reverse-engineering DUBNIUMโ€™s Flash-targeting exploit. Retrieved March 31, 2021. [11] Microsoft DUBNIUM June 2016 Microsoft. (2016, June 9). Reverse-engineering DUBNIUM. Retrieved March 31, 2021.