Also known as: DUBNIUM, Zigzag Hail, Luder, Karba, Tapaoux, Nemim, APT-C-06, SIG25, Fallout Team, Nemin, Pioneer, Shadow Crane, TUNGSTEN BRIDGE, T-APT-02, G0012, ATK52
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.(Citation: Kaspersky Darkhotel)(Citation: Securelist Darkhotel Aug 2015)(Citation: Microsoft Digital Defense FY20 Sept 2020)
Dark Hotel; Inexsmar; Daybreak; Wizard Opium; Higaisa; Information on Chinese forum indicating group may have targeted CVE-2015-8651, most likely a South Korean actor
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Darkhotel, a suspected South Korean threat group, conducts cyberespionage targeting primarily East Asian countries, focusing on government sectors and traveling executives through hotel networks. Known for long-term operations since at least 2004, they employ phishing, exploitCVE-2015-8651, and peer-to-peer infections to gather intelligence.
Goals & Targeting
Darkhotel's primary motivation is espionage, targeting government sectors to gather intelligence. Their focus on East Asian countries suggests a strategic interest in geopolitical intelligence. Typical victims include traveling executives, diplomats, and other high-profile individuals likely to have access to sensitive information while in transit or at hotels.
Enhanced Description
Darkhotel is a cyberespionage group believed to be based in South Korea, active since 2004. They primarily target East Asian countries including Russia, China, Taiwan, South Korea, North Korea, and Japan. The group gained notoriety by compromising hotel networks to target traveling executives and other high-value individuals. Darkhotel uses multiple attack vectors, including spearphishing campaigns, peer-to-peer file sharing infections, and exploiting CVE-2015-8651. Their operations often involve sophisticated techniques such as keylogging, code signing, and encryption to avoid detection. They have been linked to several campaigns like 'Wizard Opium' and 'Higaisa', which demonstrate their capability to persistently monitor targets for sensitive information.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
Darkhotel's campaigns demonstrate long-term persistence and targeting precision. Notable operations include their hotel network compromises for espionage, spearphishing efforts, and use of malicious files. The group has been observed since at least 2015, with activity continuing in recent years as noted by Microsoft in September 2020. Their victims include both governmental entities and private sector executives traveling through targeted regions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence inDarkhotel's origin as a South Korean group is moderate but widely believed within the community. Further information gaps include exact campaign timelines and specific ties to state-sponsored programs beyond known associations.
Dark Hotel
Inexsmar
Daybreak
Wizard Opium
Higaisa
No observed data linked yet.
24
Techniques
7
Tools
7
Campaigns
62
IOCs
0
Observed Data
9
Tactics