Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Darkhotel

Also known as: DUBNIUM, Zigzag Hail, Luder, Karba, Tapaoux, Nemim, APT-C-06, SIG25, Fallout Team, Nemin, Pioneer, Shadow Crane, TUNGSTEN BRIDGE, T-APT-02, G0012, ATK52

Description

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.(Citation: Kaspersky Darkhotel)(Citation: Securelist Darkhotel Aug 2015)(Citation: Microsoft Digital Defense FY20 Sept 2020)

TTP Summary

Dark Hotel; Inexsmar; Daybreak; Wizard Opium; Higaisa; Information on Chinese forum indicating group may have targeted CVE-2015-8651, most likely a South Korean actor

Goals & Targeting

Targeted Sectors

Government

Targeted Countries / Regions

RU
CN
TW
KR
KP
JP

AI Analysis

· 1 week ago

Executive Summary

Darkhotel, a suspected South Korean threat group, conducts cyberespionage targeting primarily East Asian countries, focusing on government sectors and traveling executives through hotel networks. Known for long-term operations since at least 2004, they employ phishing, exploitCVE-2015-8651, and peer-to-peer infections to gather intelligence.

Goals & Targeting

Darkhotel's primary motivation is espionage, targeting government sectors to gather intelligence. Their focus on East Asian countries suggests a strategic interest in geopolitical intelligence. Typical victims include traveling executives, diplomats, and other high-profile individuals likely to have access to sensitive information while in transit or at hotels.

Enhanced Description

Darkhotel is a cyberespionage group believed to be based in South Korea, active since 2004. They primarily target East Asian countries including Russia, China, Taiwan, South Korea, North Korea, and Japan. The group gained notoriety by compromising hotel networks to target traveling executives and other high-value individuals. Darkhotel uses multiple attack vectors, including spearphishing campaigns, peer-to-peer file sharing infections, and exploiting CVE-2015-8651. Their operations often involve sophisticated techniques such as keylogging, code signing, and encryption to avoid detection. They have been linked to several campaigns like 'Wizard Opium' and 'Higaisa', which demonstrate their capability to persistently monitor targets for sensitive information.

Key Capabilities

  • Spearphishing campaigns
  • Exploitation of CVE-2015-8651
  • Peer-to-peer file sharing infections
  • Keylogging malware
  • Code signing techniques
  • Malicious file creation and distribution

MITRE ATT&CK Tactics

Espionage
Exploitation for Client Execution
Defense Evasion
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1056.001
T1204.002
T1573.001
T1080
T1518.001
T1553.002
T1074
T1124
T1497
T1083

Campaigns & Victims

Darkhotel's campaigns demonstrate long-term persistence and targeting precision. Notable operations include their hotel network compromises for espionage, spearphishing efforts, and use of malicious files. The group has been observed since at least 2015, with activity continuing in recent years as noted by Microsoft in September 2020. Their victims include both governmental entities and private sector executives traveling through targeted regions.

IOC Patterns

  • Spearphishing emails targeting travelers
  • Hashes of malicious files (MD5)
  • Compromise via hotel or public Wi-Fi networks
  • Use of domains like 'all-microsoft-control.com' for C2
  • Encrypted/encoded communication channels

Recommended Actions

  • Monitor network traffic in hotels and high-risk travel locations for suspicious activity.
  • Educate employees on phishing tactics, especially when traveling to targeted regions.
  • Implement endpoint detection solutions to identify malicious file patterns associated with Darkhotel.
  • Conduct regular security audits of external devices used by executives.
  • Use sandboxes to analyze unknown files before allowing execution.

Suggested Tags

APT
espionage
government-targeted
South_Korea-linked
East_Asia

Confidence Assessment

Confidence inDarkhotel's origin as a South Korean group is moderate but widely believed within the community. Further information gaps include exact campaign timelines and specific ties to state-sponsored programs beyond known associations.

ATT&CK Techniques

Discovery
6 techniques
Stealth
6 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 1 URL 8 SHA-256 Hash 5 SHA-1 Hash 5 MD5 Hash 1

References

  1. Securelist Darkhotel Aug 2015 — Kaspersky Lab's Global Research & Analysis Team. (2015, August 10). Darkhotel's attacks in 2015. Retrieved November 2, 2018.
  2. Kaspersky Darkhotel — Kaspersky Lab's Global Research and Analysis Team. (2014, November). The Darkhotel APT A Story of Unusual Hospitality. Retrieved November 12, 2014.
  3. Microsoft Digital Defense FY20 Sept 2020 — Microsoft . (2020, September 29). Microsoft Digital Defense Report FY20. Retrieved April 21, 2021.
  4. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  5. Microsoft DUBNIUM July 2016 — Microsoft. (2016, July 14). Reverse engineering DUBNIUM – Stage 2 payload analysis . Retrieved March 31, 2021.
  6. Microsoft DUBNIUM Flash June 2016 — Microsoft. (2016, June 20). Reverse-engineering DUBNIUM’s Flash-targeting exploit. Retrieved March 31, 2021.
  7. Microsoft DUBNIUM June 2016 — Microsoft. (2016, June 9). Reverse-engineering DUBNIUM. Retrieved March 31, 2021.

Intel Summary

24

Techniques

7

Tools

7

Campaigns

62

IOCs

0

Observed Data

9

Tactics

Tags

APT
Phishing
espionage
government-targeted
South_Korea-linked
East_Asia

Details

MITRE ID
G0012
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
North Korea (KP)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--9e729a7e-0dd6-4097-95bf-db8d64911383
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.